IntelliCoach Courses

IntelliCoach changelog

A plain-language history of what changed, from the first build in March to today.

  1. Release 72

    v0.74.16

    Safer access and quicker releases

    This follow-up strengthens staff sign-in protection, keeps new authoring work private by default, and reduces the amount of data copied during a release.

    • 🔐 Uses the verified visitor address for staff session protection on both the live site and Cloudflare-backed staging.
    • 📝 Starts new newsletter and podcast entries as drafts so unfinished work stays private.
    • ✉️ Prevents simultaneous requests from creating duplicate email templates.
    • ⚡ Runs independent checks side by side and sends only changed website content during production updates while preserving generated downloads.
    • 📚 Keeps the growing Lightbulb and podcast archive responsive by avoiding repeated work when an article opens or redirects.
  2. Release 72

    v0.74.15

    A clearer platform, from first visit to course access

    The main offer areas are easier to explore, the complete workshop catalog is aligned with its source material, and access, pricing, reporting, and content publishing are ready for day-to-day use.

    • Gives Group Workshops, Coaching Skills, and Resources clearer visual introductions, larger section links, consistent symbols, and location trails that make deeper pages easier to navigate.
    • Aligns all 22 workshops with their canonical product content, adds Building Trust in Teams and Self-Leadership and Personal Values, and provides updated English and German one-pagers.
    • Shows the active six-session Compact and nine-session Full programmes for leaders, HR Business Partners, and Japanese-speaking leaders, with accurate group sizes and no retired programme claims.
    • Confirms ten Lightbulb Moments published between 31 May and 2 August are current and adds twelve newer Alumni issues to the protected member library, each with its original date and cleaned reading page.
    • Shows workshop prices in SGD for Singapore, EUR across geographic Europe, and USD elsewhere or when location is inconclusive.
    • Restores login-code delivery, explains the new platform, previous IntelliCoach PRO materials, and the Leader Academy in one place, and keeps sign out within easy reach.
    • Adds a consent-gated private daily dashboard and a combined email report with production and staging shown separately, using a private server connection so both sections remain available without weakening public bot protection. It also adds a first authoring area for newsletters, blog posts, podcasts, lists, and scheduling.
    • Protects public submissions and staff sessions, enforces browser safeguards, keeps visitor data pseudonymous for 30 days, separates staff traffic, and improves the mobile practice sequence.
    • Keeps podcast, workshop, and build-log content aligned with each website release, including the complete image carousels in earlier build-log entries, and makes secure review access respond without the former wait.
    • Keeps both clickable white-paper covers at their full size while images load on phones and tablets, so the download choices remain stable and easy to tap.
    • Applies the reporting database updates already proven in staging before each production release, so the private dashboard and daily email have their required data tables from the first visit.
    • Returns staff to the login page when a protected session reaches its security time limit, replacing the confusing error page with a clear way to continue.
    • Publishes the ten latest Lightbulb Moments consistently through the live content library, so the website and its source stay on the same complete set.
  3. Release 71

    v0.71.0

    The new IntelliCoach website is live

    The rebuilt website now helps visitors find the right workshop or coaching offer, with clearer pages for Stakeholder-focused Coaching and Coaching Skills.

    • Published the Day 71 build-log entry on the five-week silence, the June target set against a heavy July, and the complete offer now sitting in one place.
    • Shipped the four-slice offer-surface redesign: chooser outcome gate, Stakeholder-focused Coaching one-pager, Coaching Skills family (landing plus People Leaders, HR Business Partners, and Japanese-speaking Leaders), and a workshop detail pass. Bilingual throughout.
    • Patched the dependency tree ahead of the unveil, closing nine Next.js advisories, and recorded the one remaining lint-only finding as a justified, time-limited exception.
    • Moved the launch-mode gate from holding to live. The holding page is retired and the site is publicly indexable for the first time.
    • Closed the build log as an email format. It was always a temporary companion to the build rather than a permanent newsletter.
  4. Release 70

    v0.70.0

    A quieter week while the next release took shape

    School holidays and client work made this a quieter build week. The next large update stayed in private review until the right tools and time were available.

    • Published the Day 70 build-log entry on strategic patience, the economics of waiting for better AI tools, and the Bill Gates 100x-programmer argument applied to AI models.
    • Heaviest foundational work continues in deliberate pause. Quiet launch target Monday June 22 remains in view.
    • Named the bar-shift moment publicly: once you have experienced what the most capable tool can do, that experience resets your acceptable floor and changes the cost calculation for going back.
  5. Release 69

    v0.69.0

    A deliberate pause for quality

    The heaviest website work paused while the main coding tool was unavailable. Feedback still moved the private preview closer to what clients need.

    • Published the Day 69 build-log reflection on building at the frontier and the volatility that comes with depending on one tool at the very front of what is possible.
    • Held a deliberate pause on the heaviest foundational work until the most capable tool is available again, to avoid the rework a weaker substitute would cause.
    • The private team-only preview reached a more customer-focused state, shaped by feedback gathered during the break rather than by new building today.
    • Named a new concentration risk publicly: leaning your whole weight on one frontier tool means someone far away can move it out of reach for reasons unrelated to you.
    • Nothing went public: no domain change, no payments, no emails, nothing live.
  6. Release 67

    v0.67.0

    Clearer visuals and a safer website

    A confusing illustration was replaced, every future image now gets a meaning check, and a security update went live the same day.

    • Published the Day 67 build-log reflection on the J curve, lost days, and planning for the dip.
    • Codified a sense check for every generated image: each picture is viewed and gated for scene logic, cold-viewer story, exact text, mood, and brand before it ships.
    • Replaced the Day 66 build-log image with the nap-nest version across the live site, the LinkedIn pickup, and the newsletter banner.
    • Added an optional handwritten-style note line to the newsletter template and re-sent the Day 66 EN and DE newsletters with the corrected picture.
    • Patched the login library against a fresh severity-7.6 advisory and deployed it to production the same day.
  7. Release 66

    v0.66.0

    Longer projects now stay on track

    A new working rule helps the build stay consistent after long AI sessions reset. The private homepage preview also moved forward.

    • Published the Day 66 build-log reflection on AI memory limits and the read-the-plan-first rule.
    • Locked the standing rule for both coding tools: after every memory reset, read the unchanging master plan before the self-written summary.
    • Advanced the new front page to its next private preview version, driven entirely by spoken and written feedback with screenshots.
    • Named the transferable lesson: a great summary is not a great memory; handovers hold when the unchanged plan is read first.
    • Kept everything private and gated: no domain change, no payments, no emails, nothing public.
  8. Release 65

    v0.65.0

    The new homepage took a big step forward

    Legacy course material was recovered from the old platform, and the new private homepage reached roughly 90% completion.

    • Published the Day 65 build-log reflection on autonomous delegation and trusting first, then checking.
    • Ran two unattended OpenAI Codex goal sessions to extract legacy course material from a closed platform and rebuild a new front page.
    • Stood up the new front page for the migrated course content, now around ninety percent and still in private review.
    • Named the tool-fit difference plainly: Codex runs long, self-checking goal sessions today; Claude does not yet.
    • Kept everything private and gated: no domain cutover, no payments, no emails, nothing public.
  9. Release 64

    v0.64.0

    Private review opened for the new website

    Named reviewers could access the rebuilt website in a protected preview while the public site stayed unchanged.

    • Published the Day 64 build-log reflection on theory of mind and the jagged frontier.
    • Moved the new IntelliCoach.com into a private, gated review space that named reviewers can open.
    • Replaced the previous access gatekeeper with an app-level email and PIN gate, and verified reviewer access for all three reviewers.
    • Corrected a reviewer's short email address so it resolves to the right account.
    • Kept production, domain cutover, payments, email, and the legacy marketing stack gated and unchanged.
  10. Release 58

    v0.58.0

    A simple rule for more reliable updates

    The build process now finishes one request before starting the next, reducing half-finished changes and rework.

    • Published the Day 58 build-log story about trust, verification, and changed AI workflow behavior.
    • Captured a new sequencing rule for AI coding tasks with follow-up requests.
    • Framed the lesson through the familiar management pattern of noticing when a collaborator's context or communication has changed.
    • Kept product build work, content-system testing, import work, payment work, domain work, and homepage implementation outside this content route.
  11. Release 57

    v0.57.0

    A short update and a clearer launch countdown

    Work stayed light while Maik recovered. The public build counter and the June 15 target were updated.

    • Published a short English build-log note for a recovery day, with no hero image by request.
    • Published the matching German build-log note and kept the newsletter source bilingual.
    • Moved the public go-live target to 15 June 2026 and separated content day from public Build day counter.
    • Codified Build day wording so public posts stop using denominator or remaining-days language.
  12. Release 56

    v0.56.0

    A better way to edit long-form content

    A long manuscript found the right editing workflow, while the bilingual content and newsletter paths moved forward.

    • Published the Day 56 build-log story about separating coding work from creative manuscript editing.
    • Framed the lesson as role fit: do not assign work to an AI just because it can technically attempt the task.
    • Added English and German public entries based on Maik's 2026-05-25 brain dump, with the correct source-day framing for tomorrow's LinkedIn pickup.
    • Selected the version-five dramatic creative-editing visual for the build-log and newsletter path.
    • Updated the DPP ship-it rule so future approvals name the lists first and then proceed through content publication, newsletter sending, bookkeeping, and closeout.
  13. Release 53

    v0.53.0

    A new story about safe experiments

    A new build story used the idea of branching paths to show how low-cost experiments can improve AI-supported work.

    • Published the Day 53 build-log story around forking an AI conversation so an alternate path can be tested without damaging the original thread.
    • Framed forking as an experimenting habit: create a bounded alternate path, observe it honestly, then decide which version earns the right to continue.
    • Moved the public content cycle forward through the content route while keeping checked-in JSON aligned as the rollback source for the CMS-backed path.
    • Added the selected literal fork visual, blog hero, newsletter banner, LinkedIn pickup image, and paired fork image candidates.
    • Kept LinkedIn publication as a Maik-manual Monday pickup and kept newsletter sending behind the explicit post-deploy send approval gate.
  14. Release 52

    v0.52.0

    A new story about keeping AI work on track

    A new story explained how rewinding an AI session can clear a bad direction without losing the useful work.

    • Published the Day 52 build-log story around rewind as a way to remove a wrong turn from AI working memory.
    • Framed the lesson as a choice between repairing after a mistake and preventing damaged context from becoming part of the work.
    • Used the CMS-backed content path for the Day 52 ship while keeping checked-in JSON aligned as the rollback source.
    • Added the selected pink-elephant visual, blog hero, newsletter banner, LinkedIn pickup image, and paired image-candidate files.
    • Codified the future DPP image handoff rule: five clean blog/base images and five matching LinkedIn typography images as separate paired files.
  15. Release 51

    v0.51.0

    A new story about leading several AI helpers

    A new story looked at the challenge of leading several AI helpers at once, with a clearer rule for choosing images.

    • Published the Day 51 build-log story around AI work becoming another inbox to lead.
    • Framed parallel AI sessions through span of control, with roughly five to eight sessions as the manageable range and twelve as too many.
    • Added the selected octopus visual, blog hero, newsletter banner, and next-day LinkedIn pickup image.
    • Added DPP-R-037 so future blog drafts require five actual image candidates before review handoff.
    • Kept newsletter sending and manual LinkedIn posting as separate gates after the platform content ship.
  16. Release 50

    v0.50.0

    Clearer goals for AI-assisted work

    The project added clearer checks for goals and plans so technical work stays connected to the result people should experience.

    • Codified a clearer AI decision format: context, options, and recommendation.
    • Added a vision-and-plan check so AI agents show both the plan and the intended direction before answering.
    • Created a staging platform on the home server for safer testing before production changes.
    • Built a workflow to refresh staging with real live-platform user data.
    • Published the Day 50 build-log story around systems thinking, coaching skill, and visible vision statements for AI work.
  17. Release 49

    v0.49.0

    The first learning product moved into real production work

    STARQ Feedback Mastery moved from planning into real source work while the private test environment progressed.

    • Added a plan-checking hook pattern to keep long AI sessions aligned with the current project case file before work begins.
    • Moved STARQ Feedback Mastery into concrete source work: the first product idea is locked and its source package is ready for Maik review before Build starts.
    • Advanced the staging path: the Synology staging origin, protected public path, and repeatable production-to-staging refresh are in place, with browser access still the remaining blocker.
    • Published the Day 49 build-log entry around the nurse handover and case-file metaphor for AI continuity.
  18. Release 46

    v0.46.0

    Stronger checks before new features ship

    New checks now make important architecture decisions visible before work begins, reducing avoidable rework.

    • Added the ADR source-trace gate so future DPP strand reports must cite topic-relevant architecture decisions before making product, platform, or governance claims.
    • Re-grounded the paid-PDF bundle standard: free executive-review preview pages remain readable, while main-content pages keep readable chrome and irreversibly masked body content.
    • Prepared the Day 46 blog, newsletter, changelog, and image-concept review packet from Maik's evening brain dump.
    • Kept Day 45 LinkedIn, Day 45 newsletter resend, STARQ Product1 Think, and development strands closed for tonight's content-only route.
  19. Release 45

    v0.45.0

    The first break-in attempt was blocked

    The website blocked its first real intrusion attempt. The protection and monitoring rules were tightened after the alert.

    • First real break-in attempt detected and blocked; the affected access flow was hardened after review.
    • Monitoring caught an over-broad protection response when the hourly email check failed, proving the alerting path worked.
    • P-016 project-router framing now governs DPP daily work, with DPPG-R-009 requiring objective, boundary, proof target, success criteria, bigger-picture fit, and unproven items for non-trivial deliverables.
    • Day 45 content prepared for platform publication, with blog, changelog, newsletter, LinkedIn draft, and image assets moving through the governed content cycle.
  20. Release 43

    v0.43.0

    Better mobile and accessibility testing

    Key pages gained wider phone, tablet, and accessibility coverage before the next release.

    • LS-C07 completed: Playwright now covers desktop Chrome, iPhone 13, Pixel 7, and iPad profiles.
    • Homepage end-to-end coverage now exercises small-screen navigation and the mobile feedback control.
    • LS-C08 completed: axe-core coverage added across five flagship pages in English and German.
    • Shared UI/page surfaces adjusted for accessible labels, page language, semantic button behavior, and readable contrast.
    • docs/TESTING.md updated with the new mobile and accessibility coverage expectations.
    • docs/LAUNCH-SCOPE.md and docs/LAUNCH-READINESS.md updated: LS-C07 and LS-C08 now pass, while full-environment rerun and visual spot-check remain tomorrow follow-ups.
  21. Release 42

    v0.42.0

    The next chapter of products started

    The next homepage, legal review, private staging setup, and first product content were formally added to the release plan.

    • Two historical-gap tombstones added for Day 35 (Fri 5-1, Singapore Labour Day) and Day 36 (Sat 5-2, weekend DEV), both days remain in the counter, framed honestly as 'no public entry.'
    • First product content authorship runway opened (LS-C10, STARQ Feedback Mastery). Multi-session build phase begins this week using parallel Opencode sessions; product subdirectories and content-status.json scaffolding committed.
    • LS-S11 Stalwart credential rotation accepted as post-launch sweep work alongside LS-S12 admin-endpoint hardening.
    • LS-C11 new marketing homepage queued for the launch-week build slot. Replaces the current build-log-as-homepage; build log moves to /build-log.
    • LS-L08 amended to fold the 'lifetime access' fine-print disclosure into the next iubenda terms + lawyer review pass.
    • LS-O06 Synology DS1525+ staging environment queued for the launch-week buffer slot.
    • LS-S13 Vercel DeepSec agent-driven SAST scan queued for pre-launch QA week, additive to the existing Semgrep + CodeQL + gitleaks + OSV scanners.
    • Quick-path daily content workflow codified in the memory wiki, when Maik signals tired or one-shot mode, the standard cycle collapses into a single-turn produce-and-present.
  22. Release 41

    v0.41.0

    A cleaner, more reliable release process

    Version labels, records, newsletter safeguards, and automated checks were brought back into alignment.

    • ADR 058 added: no branching, every commit lands on main. Supersedes the durable-branch isolation aspect of ADR 031. Locks tagging-only-on-main, deploy-only-from-main, and a session-start orphan-branch scan as MANDATORY.
    • 17 stale local branches (claude/*, day26/*, worktree-agent-*, _a/_b/_c) and 4 stale remote branches deleted. 10 mounted worktree directories force-removed. Repo state: main only, local + remote.
    • Tag v0.40.1 created on main HEAD as the recovery release combining Day 40 evening UI work with the Day 41 governance close-out. v0.40.0 preserved as historical anchor for the Day 40 deploy state.
    • scripts/send-newsletter.ts hardened: rejects any unknown flag or extra positional argument with a clear error pointing to newsletter-template.ts for fragment-only previews. Closes the Day 41 --dry-run footgun that fired an unauthorized send to 4 EN subscribers.
    • scripts/validate-launch-scope.ts now exits 1 on structural failures (silent-pass placeholders) per ADR 050, not just on blocker check failures. Validator is now the gate ADR 050 specified.
    • ADR 052 amendment: 09:00 SGT cron and in-repo docs/audit/ output path accepted as the binding implementation. ADR is now historical record; cron script run_dpp_codex_weekly_audit.sh is canonical.
    • force-dynamic on product + bundle pages so signed waiver-intent tokens mint per request once NEXT_PUBLIC_CHECKOUT_ENABLED flips. Closes the FIXME from b7162de.
    • Day 41 build log entry shipped (Today I paid governance interest). Friday Lightbulb Moments Build Log recap drafted for Sunday 5-10 send.
  23. Release 40

    v0.40.0

    Clearer privacy choices and a new legal notice

    Visitors now get clearer privacy information, location-aware cookie choices, and a bilingual legal notice.

    • CCPA / CPRA chrome callout shipped on /legal/privacy in EN and DE. Server-rendered, reuses DPO_EMAIL from src/lib/dpo.ts. LS-L03 closed.
    • Imprint route /legal/imprint live in EN and DE. TMG §5 + MStV §18(2) compliant, footer-linked. Surfaced same-day after the iubenda scan flagged the Baden-Württemberg DPA accessibility requirement.
    • iubenda integration verified live with all 9 sub-processors present in the policy body (Whop, Hetzner, OVHcloud, Cloudflare, Listmonk, Stalwart, Postfix, Better Auth, iubenda). Banner mounted root-layout with beforeInteractive load. EU geo-targeting confirmed from a Helsinki exit; Singapore correctly suppresses the banner per PDPA. LS-L01 verified.
    • next-intl bumped to ^4.11.0, clearing GHSA-4c35-wcg5-mm9h and GHSA-r27j-894h-3w3p in transitive icu-minify. Imprint route still HTTP 200 after redeploy.
    • Day 40 build log entry shipped (frog metaphor, launch-shift braided in, Baden-Württemberg quirk named explicitly). Day 39 placeholder entry shipped to keep the build-day count honest after a sick day.
    • Launch date shifted from Tuesday 2026-05-12 to Monday 2026-06-01 (Day 57). Reason: one sick day plus the still-running audit list plus regulatory items the iubenda scan surfaced. Buffer is necessary but not sufficient.
    • ADR 057 supersedes ADR 023, recording the launch-shift rationale and the version-one-not-beta-one principle.
  24. Release 39

    v0.39.0

    A quiet recovery day

    No product changes were released while Maik recovered. The date remains in the history so the record stays honest.

    • Day 39 build log entry shipped (no shipping; second recovery day after Day 38 sick day, written for the count to stay honest).
  25. Release 38

    v0.38.0

    A sick day, recorded honestly

    No product changes were released. The build log simply records that Maik was unwell and took the day off.

    • Day 38 build log entry shipped to content/roadmap/{en,de}.json. Headline: I had to admit defeat today. Stats bumped: daysIntoJourney 37 to 38, progressPercent 88 to 90.
    • LinkedIn post folder for tomorrow skipped per Maik's explicit instruction. Image-concepts task deferred. The Day 35 + Day 36 + Day 37 LinkedIn catch-up cycle rolls forward to the next session.
  26. Release 37

    v0.37.0

    Security, email reliability, and monitoring improved

    Three urgent review findings were fixed. Email backup, off-site monitoring, and credential security also improved.

    • Three P1 audit findings shipped via parallel orchestrator-subagent dispatch: pre-checkout consent record now reconciles to the actual purchase via the canonical product id, the consent-record API is gated by a server-issued short-lived signed waiver intent, and the executive-summary preview email now sends per-recipient via Listmonk transactional rather than as a broadcast campaign.
    • DPP database password rotated end-to-end after a brief plaintext exposure during a chat session. Postgres role updated, .env rewritten on VPS, dpp container recreated, live verified.
    • Repo-level gitleaks allowlist (.gitleaks.toml) added for documentation cite-key slugs and unit-test fixture credentials. Reduces five recurring false positives to zero.
    • Codex weekly audit cron PATH bug fixed (Sunday 5-3 audit had failed exit 127 because /opt/homebrew/bin was not on the cron-spawned shell PATH). Sun 5-3 audit back-filled, captured the same 3 P1 findings.
    • Backup MX live for inbound mail via DNSExit Foundation tier on intellicoach.org + intellicoachcourses.com (LS-O05 closed). Loki + Grafana + Promtail observability stack live on Synology, mail-loop monitor running, Borg restore drill end-to-end pass (C-021 sessions 8-10).
    • Voice-learnings doc seeded L-004 from yesterday's published Day 34 LinkedIn post: nine candidate patterns including tool-name precision (Claude Code vs Claude), no markdown in LinkedIn comments, and self-bio numbers computed from the project anchor date.
    • ADR 054 locks the Stalwart-VPS-as-DPP-dependency relationship; ADR 055 locks the LS-L07 reconciliation key (product id, not plan id) with a regression-guard test. LS-S12 added (medium, post-launch) for two Stalwart admin-endpoint hardening findings the Borg drill surfaced.
    • Day 37 blog records that the launch date Tuesday 2026-05-12 is under serious contemplation. Sitting with the still-open audit items has Maik reconsidering whether that Tuesday is the right Tuesday. No decision yet.
  27. Release 34

    v0.34.0

    A clearer checkout and a new founding-member offer

    The site added a founding-member offer and a clearer consent step before checkout, alongside several security follow-ups.

    • Stalwart feedback@ password rotated and shared agent skill files redacted after yesterday's external audit found a plaintext credential. Gitleaks history sweep confirmed no further exposures.
    • Article 16(m) digital-goods consent gate wired into the pre-checkout flow, plus an extended-preview alternative form for buyers who want more before paying.
    • Founding Members surface live: first-50 signup counter, 30% bundle promo code, founding-member badge, and the entitlements column that backs all three.
    • My Account skeleton with five tabs (Dashboard, Purchases, Subscriptions, Profile, Settings) and authentication gating in place. Deeper per-tab content lands tomorrow.
    • Voice-learnings doc seeded two new long-term rules from yesterday's published LinkedIn post: a publish-time tense pass on every LinkedIn draft, and a humble-voice principle that anchors every blog and post.
    • Three sister skills scaffolded for the three-week product cycle (think, build, sell), with the first flagship product seeded for the launch-day Build week.
    • Five new architecture decision records landed (049 through 053): iubenda integration, validator placeholder discipline, Codex as permanent second voice, Sunday Codex audit cadence, three-week product cycle.
    • New Status Card PDF reference card auto-generates a multi-page status overview at every session open, written to a new DPP/Project Status folder.
  28. Release 33

    v0.33.0

    An independent review found real security issues

    A fresh review by a second AI found several meaningful issues, including an exposed password that was then addressed.

    • Codex confirmed as permanent second voice in the project, alongside Claude, not just a one-day workaround
    • External Codex audit identified one plaintext access password in a shared agent skill file (line 657 of agent-commons/skills/maik-dpp/SKILL.md). Redaction and rotation queued for Day 34
    • External AI audit pattern locked: when main development tool is unavailable, ask the secondary tool for an outside read of the whole project
    • Newsletter image format standard codified: crop the HBR top band off, 600px wide JPEG at 80% quality, target under 80KB, banner under the navy header (cite-key dpp-newsletter-image-format)
    • DPP image quality bar codified: LinkedIn keeps HBR band 1024px+, newsletter banner per Standard 1, blog inline 1024-1600px WebP at 80%, mobile-LTE under 1.5s render bar (cite-key dpp-image-quality-bar)
    • Block-leave facts corrected in skill memory: practice applies to specific regulated roles only (traders, settlements), two consecutive weeks, two stated reasons (wellbeing plus control by absence), not an audit, no presumption of guilt
  29. Release 32

    v0.32.0

    A second reviewer joined the build

    A second AI reviewer joined the project, several small interface problems were fixed, and the publishing record was cleaned up.

    • Codex 5.5 added as project-management co-lead alongside Claude, shared notes folder set up at the orchestrator level
    • Three-AI parallel researcher pattern: same question fans out to Codex, Gemini, and Claude; Claude compares the three answers and names strengths and weaknesses of each
    • Footer Turnstile switched to invisible mode (data-execution=execute + appearance=execute + execute callback per Cloudflare's documented invisible pattern, not the non-existent data-size=invisible)
    • Manrope replaces Fraunces as the display font, weights 400/600/700, applied via next/font/google
    • Asymmetric corner utility rounded-asym-xs (8px 0 8px 0) added to globals.css and applied to the NavAuthButton login pill
    • Footer responsive grid changed from md:grid-cols-4 to md:grid-cols-2 lg:grid-cols-4, fixes subscribe-button overlap at 768-1024px viewports
    • Translation fix on messages/en.json footer.otherLangLink: Subscribe auf Deutsch -> Auf Deutsch abonnieren ->
    • voice-learnings.md canonical artifact landed at docs/voice-learnings.md, 23 confirmed voice patterns, 8 candidate gaps, 6-element governance cycle, L-001 seed entry from commit 26f19ca (best -> right)
    • Notion publications cleaned up: Day 12 LI confirmed-not-published, Apr 23 entry renamed Day 27 -> Day 26 (resolves two gaps), Day 25 NL-DPP DE duplicate archived
    • Skill rule locked: Behind-the-curtain and Changelog must always be separate LI comments (cite-key dpp-linkedin-behind-curtain-changelog-separate); per-comment char count ≤1200 with 50-char headroom (cite-key dpp-linkedin-comment-char-limit); -maik suffix convention for draft preservation
    • MANDATORY SESSION START Step 1.6 added: acknowledge-on-receive ritual when a -maik.md companion file is found in the most recent LI post folder
  30. Release 31

    v0.31.0

    Stronger legal, backup, and design foundations

    The project added a monthly restore drill, real privacy tools, clearer refund terms, and a consistent design for documents.

    • Monthly database restore drill scripted and ran successfully for the first time, full snapshot restored to scratch in 20 seconds (LS-S01, Sat)
    • Real iubenda integration shipped, privacy plus cookies plus terms now stream from iubenda's API with a one-hour cache, real consent banner replaces the placeholder (LS-L01, Sun)
    • Executive summary PDF pipeline end to end, 45-page full document plus 45-page preview with irreversible body obfuscation per ADR 048, purchase CTA on page 5 (LS-P02, Sun)
    • No-refund policy text published with Article 16(m) digital-goods waiver framing, extended-preview-on-request alternative, defective-product carve-out, Whop merchant-of-record pointer (LS-L05, Mon)
    • Centralization Principle locked as a foundational platform rule, one canonical source per concern, surfaces compose rather than duplicate (Sat)
    • Design system pass 2, three new shadow utilities, ProductCard and BuildLog now compose the canonical Card component, Footer subscribe button uses the Button component, 19 arbitrary Tailwind values eliminated (Sat)
    • Typography migration completion, Roboto removed across 8 sites, Fraunces applied to hero h1 plus blog day headlines plus 5 editorial surfaces (Sat follow-up)
    • Legal Attestation signed by IntelliCoach Pte Ltd for European Union plus Singapore plus United Kingdom plus United States with California CCPA in scope (LS-L04)
    • ADR 014 (iubenda integration) plus ADR 048 (PDF preview Hybrid E obfuscation) plus 24 backfilled ADRs covering Days 6 through 28 added to docs/decisions/
    • Seven new launch-scope items codified, LS-L06 extended-preview form, LS-L07 Article 16(m) checkout consent capture, LS-L08 portal sweep plus lawyer review, LS-A01 Attention Insight pre-launch pass, LS-A02 Plerdy install plus iubenda consent wiring, LS-A03 analytics API integration deferred, LS-A04 daily database diff deferred
    • IntelliCoach document design language locked, warm Brene-leaning workbook style refined with Fraunces typography weight pushed to 600 to 700 on display roles, validated reference at pdf-doc-warmth-fraunces-bold.html
    • Page-Fit Algorithm v1 specified, five-pass page-splitting pipeline (preprocessor, render via Playwright on Chromium 108+, measure, re-balance, verify), grounded in Knuth-Plass plus CSS Fragmentation Level 3 plus Chromium RenderingNG
    • Day 28 LinkedIn post published, 'A toast to the work nobody sees', full standard structure with Who/What/Why plus Journey plus Behind-the-curtain comments and emoji-categorized changelog highlights
    • maik-iubenda Claude Code skill activated at ~/.claude/skills/maik-iubenda/SKILL.md for future iubenda touchpoints
    • Filing convention YYYY-MM-DD-HHMM applied across DPP working folders, 20 folders renamed (LinkedIn folders excepted)
  31. Release 30

    v0.30.0

    Clear privacy information and free product previews

    Privacy, cookie, and terms pages now come from iubenda. Product pages gained a free 45-page preview before purchase.

    • iubenda integration shipped via Pro x 1 plus backend API embed (English-only locked pre-launch, German deferred per budget cycle), one-hour cache, real consent banner replaces the placeholder (LS-L01)
    • Executive summary PDF pipeline end to end, 45-page full document plus 45-page preview with locked Level 5 obfuscation (downscale 500, sigma 2.0, q 48), purchase CTA on page 5 (LS-P02)
    • 10-level diagnostic ramp tool for visual confidence in the obfuscation severity
    • Legal Attestation signed by IntelliCoach Pte Ltd for European Union plus Singapore plus United Kingdom plus United States with California CCPA in scope (LS-L04)
    • ADR 049 (iubenda integration via Pro x 1 plus backend API embed; renumbered from ADR 014 on Day 34 due to a numbering collision with the Assume Failure ADR) and ADR 048 (PDF preview Hybrid E obfuscation) added to docs/decisions/
    • maik-iubenda Claude Code skill activated at ~/.claude/skills/maik-iubenda/SKILL.md for future iubenda touchpoints
  32. Release 28

    v0.28.2

    Six launch blockers cleared

    Six urgent launch items were completed, and automated checks were aligned with the checks run before each change.

    • Content-Security-Policy-Report-Only header and /api/csp-report endpoint live (LS-S06)
    • CI Security Gates workflow shipped: gitleaks, OSV-Scanner, Semgrep, CodeQL on every push (LS-S07)
    • Zod validation and Redis-backed rate limiting on /api/subscribe and /api/feedback/send (LS-S03)
    • Sentry scaffold (DSN-less no-op) and ntfy Sev-1 reporter wired into the Whop webhook (LS-S09)
    • Founding-member entitlement columns and migration 0005 (LS-F04)
    • FoundingMemberBadge component with EN/DE copy (LS-F03)
    • Pre-push hook now shadows CI: gitleaks plus Semgrep plus OSV-Scanner run before every push, ~31 seconds total
    • npm version pinned via .nvmrc, .npmrc, and engines block so local resolution matches the CI lane
    • Lightbulb Moments Build Log recap draft saved for Sunday newsletter (LS-C03)
    • Newsletter template now includes a per-version changelog link
  33. Release 27

    v0.27.0

    Safer public pages and a more complete About page

    Public pages gained stronger protection, better search and sharing information, and a real portrait on the About page.

    • Cloudflare WAF + Bot Fight Mode on public endpoints
    • Turnstile widget on the footer subscribe form
    • Coolify admin port 8000 locked to Tailscale via Hetzner firewall
    • Sitemap.xml (dynamic) + robots.txt shipped
    • OpenGraph image + metadata block live on every locale route
    • About page shows a portrait photograph
    • LAUNCH-SCOPE governance harness (LS-* tracker) added
    • Day 27 blog entry published EN+DE; newsletter sent
  34. Release 26

    v0.26.0

    Safer software and a clearer visual style

    The platform received an important security update and adopted a warmer headline style.

    • Next.js bumped to 16.2.4 (CVE GHSA-q4gf-8mx6-v5v3 mitigated)
    • Fraunces display face locked for hero + editorial headlines
    • System body font stack adopted (no download, native feel)
    • MANIFEST section 3 typography block updated
    • Day 26 watermelon-status blog entry published EN+DE
  35. Release 25

    v0.25.0

    The checkout now keeps your email consistent

    After a purchase, account setup now uses the same email confirmed at checkout. The release checklist also gained stronger testing rules.

    • Post-purchase sign-up form locked to payment-provider email
    • Testing regimen added to public roadmap as foundation piece
    • Session kickoff live-state check flags obvious gaps automatically
    • Five ADRs written covering the testing decision set
    • Day 25 blog entry published EN+DE
  36. Release 24

    v0.24.0

    The first complete purchase journey worked

    A full test purchase reached the buyer's account, including checkout, payment confirmation, passwordless signup, and purchase history.

    • End-to-end paid checkout verified (test promo, real webhook)
    • Whop webhook writes purchase into platform DB
    • Branded success page after checkout
    • Purchase visible on /account after magic-link signup
    • Day 24 blog entry published EN+DE
  37. Release 23

    v0.23.0

    Stronger account and payment protection

    Logged-in pages gained clearer access rules, session checks, fresh sign-in for sensitive actions, and signed payment messages.

    • Authorization policy layer for logged-in routes
    • Session fingerprint check (network + device drift detection)
    • Fresh-reauth gate on sensitive actions
    • Standard Webhooks signature verification on payment webhooks
    • Parallel subagent workflow proven on four concurrent features
    • Day 23 blog entry published EN+DE
  38. Release 22

    v0.22.0

    Passwordless sign-in and the first account page

    Visitors could sign in by email link, pass a bot check, open a basic account page, and see the correct account navigation.

    • Magic-link login via Better Auth + Postfix SMTP relay
    • Cloudflare Turnstile via Better Auth captcha plugin
    • Minimal /account page with session display + sign-out
    • Auth-aware navbar shows Login or Account
    • add-secret tooling for safe credential handling (no chat exposure)
    • Three Stalwart mailboxes provisioned: login@, team@, support@
    • ADR 014 written: Assume Failure infrastructure guardrails
    • Day 22 blog entry published EN+DE
  39. Release 21

    v0.21.0

    Secure account foundations and encrypted backups

    The account system, private database, encrypted backups, and managed secrets were prepared as one secure foundation.

    • Better Auth configured with magic-link + optional passkey
    • Dedicated Postgres DB for auth on internal Docker network
    • Encrypted off-site backups streamed to NAS over Tailscale
    • SOPS-managed secrets with no hardcoded fallbacks
    • Written security document targeting OWASP ASVS Level 2
    • Day 21 blog entry published EN+DE
  40. Release 20

    v0.20.0

    The database and backup routine were tested

    The future account database was created, and the encrypted backup routine was rehearsed before customer data arrived.

    • Dedicated Postgres container ("locked room") for future auth data
    • Rehearsed encrypted backup routine to home NAS over Tailscale
    • ADR 013 decision journal started (architecture record format)
    • Self-review process tightened on new work
    • Day 20 blog entry published EN+DE
  41. Release 19

    v0.19.0

    Core website security is in place

    Security headers, a public security contact, and a full surface scan completed the first protection layer.

    • Six security headers added via Next.js middleware (XFO, XCTO, Referrer-Policy, Permissions-Policy, COOP, HSTS)
    • security.txt published per RFC 9116
    • Deleted dead code containing hardcoded fallback secret
    • Surface audit: gitleaks + Semgrep clean
    • Handover document (Hemingway bridge) pattern adopted
    • Day 19 blog entry published EN+DE
  42. Release 18

    v0.18.0

    A week spent narrowing the plan

    The build paused to reduce scope and commit to the next foundations: accounts, payments, and the database.

    • Weekly review logged; perfectionism pattern named (CliftonStrengths Maximizer)
    • Next-week commitments recorded: DB, authentication, payments
    • Day 18 blog entry published EN+DE
  43. Release 17

    v0.17.0

    A better way to prevent repeated mistakes

    A configuration problem became a permanent guardrail so future sessions catch the same mistake automatically.

    • Auto-compaction incident diagnosed (1M context not enabled)
    • Skill self-editing pattern adopted: yesterday's mistake = tomorrow's guardrail
    • Positive-framing rule added to the skill (tell AI what to do, not what not to do)
    • Day 17 blog entry published EN+DE
  44. Release 16

    v0.16.0

    A clearer visual style for project updates

    Project updates gained a consistent image style after comparing several ways to create readable graphics.

    • LinkedIn image generation via fal.ai nano-banana
    • ADR 009 LinkedIn image visual language written
    • Image engine comparison documented (Gemini, Chrome overlay, fal)
    • Day 16 blog entry + LinkedIn Post 5 published
  45. Release 15

    v0.15.0

    The platform became bilingual

    English and German pages now share one structure, with natural German copy, a language switcher, and the real navigation.

    • German transcreation for 13 blog entries + 6 product pages
    • Real platform navigation (Products, Bundles, Courses, About, Contact)
    • Language switcher wired end-to-end
    • Mockup split to standalone mockup.intellicoachcourses.com
    • German style guide written (informal "du", natural voice)
    • Day 15 blog entry published EN+DE
  46. Release 14

    v0.14.0

    Roadmap, store, and preview came together

    The roadmap, store, and preview moved into one bilingual app, laying the groundwork for accounts and sign-in.

    • Three separate sites merged into one Next.js app
    • Roadmap page rebuilt as 11 reusable components
    • Bilingual routing via next-intl (/en/, /de/)
    • Nav simplified to Roadmap / Current / Mockup
    • Cloudflare DNS + Docker restructure for new architecture
    • Day 14 blog entry published EN+DE
  47. Release 12

    v0.12.0

    A clearer public build story

    The roadmap gained a clearer build log and better project context, while an email relay problem was fixed.

    • Manifest written (vision + North Star)
    • Build Log started (running decision record)
    • maik-dpp Claude skill scaffolded (process learnings)
    • SMTP relay unbanned on Stalwart (fail2ban exception added)
    • LinkedIn image branding workflow built
    • Day 12 blog entry + LinkedIn Post 2 published
  48. Release 11

    v0.11.0

    More reliable email and the first public update

    Email delivery became more reliable, the first LinkedIn update went out, and a regular publishing rhythm began.

    • SMTP HELO/hostname mismatch fixed, mail now lands in inbox
    • DKIM, SPF, PTR DNS records tightened (OVH API)
    • Postfix identity aligned with sending domain
    • LinkedIn Post 1 published (build-in-public series kickoff)
    • Publishing rhythm locked: blog same day, LinkedIn next day
    • Day 11 blog entry published EN+DE
  49. Release 10

    v0.10.0

    A clearer homepage and easier sharing

    The homepage explains what is being built, why it matters, and who it is for. Every build entry can now be shared directly.

    • Hero redesigned with What/Why/Who cards
    • Hero image optimised (24x smaller)
    • Direct anchor links on every build log entry
    • Collapsible Behind the Scenes section per entry
    • Voice-note-to-blog-draft AI skill built
    • Day 10 blog entry published EN+DE
  50. Release 9

    v0.9.0

    Roadmap, store, and preview moved under one roof

    The roadmap, store, and preview became one connected experience, and newsletter signup was tested from start to finish.

    • Traefik routing unified roadmap + store + mockup under one domain
    • Cross-experience navigation bar added
    • Purchases disabled with "Coming May 2026" placeholder
    • Newsletter signup tested end-to-end (double opt-in live)
    • Daily workflow mode added to AI orchestration skill
    • Day 9 blog entry published EN+DE
  51. Release 8

    v0.8.0

    A Sunday for family and new ideas

    No product changes were released. Ideas for the following week were captured.

    • Planned day off; no deploys
    • Day 8 blog entry published EN+DE
  52. Release 7

    v0.7.0

    A planning day for the week ahead

    No product changes were released. The next week was planned and recorded.

    • Week-ahead planning session logged
    • Day 7 blog entry published EN+DE
  53. Release 6

    v0.6.0

    Client work came first

    Client coaching work took priority, so the platform paused for one day.

    • Ops-day, no DPP deploys
    • Day 6 blog entry published EN+DE
  54. Release 5

    v0.5.0

    Newsletter signup is live

    Visitors can now subscribe with email confirmation. The roadmap also gained Maik's personal letter and a simpler route to LinkedIn updates.

    • Listmonk deployed via Docker on Hetzner VPS behind Traefik
    • SocketLabs SMTP relay configured for Listmonk
    • Roadmap subscribe form with Listmonk double opt-in
    • Zernio LinkedIn integration as a Claude skill (one-command post)
    • Personal letter section on roadmap (data-driven)
    • Day 5 blog entry published EN+DE
  55. Release 4

    v0.4.0

    The complete 23-page concept is ready

    The full website concept now covers 23 pages with real images, video, and a product-preview journey.

    • All 23 pages of the mockup built in a single HTML file
    • Real product images + IntelliCoach logo integrated
    • Real video embed on product page
    • Executive summary preview flow wired
    • Mockup served by standalone nginx Docker container
    • Day 4 blog entry published EN+DE
  56. Release 3

    v0.3.0

    The public roadmap takes shape

    The first public roadmap turned the product plan into a visible, ordered list of work.

    • Master plan written; full feature set prioritised
    • Tech stack decisions locked per component
    • /maik-dpp orchestration skill scaffolded
    • Public roadmap page built from scratch
    • Day 3 blog entry published EN+DE
  57. Release 2

    v0.2.0

    The platform moved to its own server

    The website moved from Vercel to Maik's own hosted server with HTTPS and no interruption.

    • Multi-stage Dockerfile for Next.js standalone output
    • Traefik labels for automatic HTTPS (Let's Encrypt)
    • DNS cutover from Vercel to Hetzner VPS (OVH DNS)
    • Day 2 blog entry published EN+DE
  58. Release 1

    v0.1.0

    The first IntelliCoach storefront is online

    The first version included the core storefront pages and a working Whop checkout, built and deployed in one day.

    • Next.js 16 scaffold via create-next-app
    • Product data structure designed
    • Core pages built: home, products, bundles, about, checkout
    • Whop embedded checkout SDK integrated
    • First deploy to Vercel (later migrated Day 2)
    • Day 1 blog entry published EN+DE

Each entry links to the story behind the change if you want more context.