{
  "status": "defined_trial_safe",
  "generatedAt": "2026-07-25T20:09:35.113Z",
  "aiAssistantServerPlan": {
    "clientFacingPromise": "Atelier Advisor gives guided website, package, domain, hosting, support, and next-step advice from the client's Digital Readiness answers and Atelier's delivery rules. It is a decision-support assistant, not an automatic publisher or legal/compliance substitute.",
    "currentMode": {
      "label": "Local rule-based assistant",
      "active": true,
      "externalAiCalls": false,
      "strengths": [
        "safe trial operation with no token spend",
        "answers from the submitted score report and Atelier recommendation engine",
        "logs advisor sessions for admin review",
        "blocks payments, messages, provider purchases, DNS, hosting mutation, and publishing"
      ]
    },
    "productionMode": {
      "label": "Server-side AI advisor gateway",
      "active": false,
      "activationRequirement": "Enable only after provider key, durable storage, privacy notice, rate limits, budget limits, consent logging, admin escalation, and receipt logging exist.",
      "requestFlow": [
        "Client submits score or report ID plus question from the website widget.",
        "Browser sends only the question/report ID to an Atelier server endpoint; no AI key is exposed to the browser.",
        "Server validates input, rejects secrets and sensitive regulated details, checks rate limits, and loads report context.",
        "Server assembles a narrow context packet: report summary, package ladder, top-up rules, domain/hosting guidance, safe-access policy, refund/support rules, and current cost disclosures.",
        "Server calls the selected AI provider only if enabled and within budget; otherwise it falls back to the local advisor.",
        "Server returns a bounded answer with disclaimers, recommended next action, and human-review flag.",
        "Server writes advisor session, token/cost estimate, risk tags, and follow-up task to durable storage."
      ],
      "requiredServerEndpoints": [
        "POST /api/advisor",
        "GET /api/assistant/status",
        "GET /api/fullstack-commercial-stack",
        "GET /api/report/:id",
        "GET /api/site-brief/:id",
        "POST /api/project-request",
        "GET /api/admin/tasks",
        "GET /api/admin/earning-dashboard"
      ],
      "requiredEnvVars": [
        "ATELIER_ADMIN_TOKEN",
        "SUPABASE_URL",
        "SUPABASE_SERVICE_ROLE_KEY",
        "ATELIER_PUBLIC_URL",
        "ATELIER_AI_PROVIDER",
        "ATELIER_AI_LIVE_ENABLED",
        "OPENAI_API_KEY or selected provider key",
        "ATELIER_AI_MODEL",
        "ATELIER_AI_MONTHLY_BUDGET_USD",
        "ATELIER_AI_MAX_TOKENS_PER_SESSION",
        "ATELIER_RATE_LIMIT_PER_IP",
        "ATELIER_EMAIL_PROVIDER_KEY when email is activated",
        "ATELIER_PAYMENT_PROVIDER_KEY when payments are activated"
      ],
      "requiredDataTables": [
        "atelier_reports",
        "atelier_leads",
        "atelier_advisor_sessions",
        "atelier_tasks",
        "atelier_project_requests",
        "atelier_quote_drafts",
        "atelier_support_tickets",
        "atelier_launch_kits",
        "atelier_preview_approvals",
        "atelier_cost_events",
        "atelier_consent_events",
        "atelier_provider_actions",
        "atelier_human_escalations"
      ],
      "safetyControls": [
        "server-side provider keys only",
        "secret and sensitive-data rejection before model call",
        "rate limiting and bot protection",
        "monthly AI budget cap",
        "per-session token cap",
        "model fallback and local fallback",
        "no professional/legal/medical compliance validation claim",
        "human escalation for regulated, refund, legal, security, outage, payment, and domain/hosting actions",
        "receipt log for every live/tool action"
      ]
    }
  },
  "clientPaymentSummary": {
    "plainEnglishAnswer": "You are paying Atelier for strategy, design direction, professional website production, conversion structure, QA, handoff, and a clear upgrade path. You are not only paying for a page on the internet. Third-party provider costs such as domain, hosting, payment processor fees, email/SMS/WhatsApp, booking tools, builder subscriptions, and AI API usage are separate unless a written Atelier care or managed-hosting agreement says otherwise.",
    "freeBeforePurchase": [
      "Digital Readiness Score",
      "recommended website format",
      "recommended starting package",
      "recommended top-ups now/later/not-now",
      "domain and hosting guidance",
      "safe-access guidance",
      "no-pressure next step"
    ],
    "atelierFees": [
      {
        "item": "Build fee",
        "when": "one-time per project milestone",
        "paysFor": "strategy, structure, design, implementation, QA, report, handoff"
      },
      {
        "item": "Setup or migration fee",
        "when": "only if required",
        "paysFor": "moving content, configuring host/build lane, DNS plan, deployment handoff"
      },
      {
        "item": "Top-up tariffs",
        "when": "optional",
        "paysFor": "extra pages, copywriting, booking, payment flow, catalogue, portal, PWA/app route, handoff vault, growth work"
      },
      {
        "item": "Care plan",
        "when": "monthly or annual if selected",
        "paysFor": "maintenance, checks, small updates, technical monitoring, support priority depending on tier"
      },
      {
        "item": "Growth retainer",
        "when": "monthly if selected",
        "paysFor": "content, SEO/GEO improvement, conversion polish, campaign pages, reporting"
      },
      {
        "item": "Emergency or migration ticket",
        "when": "as needed",
        "paysFor": "urgent fix, outage support, host migration, recovery assistance"
      }
    ],
    "thirdPartyCosts": [
      "domain registration and renewal paid to registrar",
      "hosting or builder subscription paid to provider",
      "payment processor transaction fees",
      "email/SMS/WhatsApp provider fees",
      "booking, CRM, analytics, map, plugin, or app-store fees if used",
      "AI API token usage if a live custom assistant is activated",
      "taxes, VAT/GST, currency conversion, chargeback/dispute fees where applicable"
    ],
    "eventualRecurringCosts": [
      "domain renewal, usually annual",
      "hosting or platform subscription, monthly or annual",
      "care/maintenance plan if selected",
      "email or messaging subscription/usage if notifications are active",
      "payment processor fees per transaction if payments are active",
      "AI assistant usage if live model calls are enabled",
      "content/SEO/GEO growth retainer if ongoing visibility work is selected",
      "premium plugins, booking systems, CRM, or catalogue/store tools if the business needs them"
    ],
    "notIncludedUnlessWritten": [
      "domain purchase",
      "hosting purchase",
      "payment processing setup with live keys",
      "message sending",
      "legal, medical, financial, or regulatory approval",
      "search-position or revenue outcome promise",
      "open-ended revision, refund, or lifetime support promises",
      "public publishing or DNS mutation before approval"
    ]
  },
  "providerCostReferences": [
    {
      "provider": "OpenAI API",
      "purpose": "Optional server-side AI assistant answers, brief expansion, and internal production support.",
      "publicSource": "https://platform.openai.com/docs/pricing/",
      "currentReference": "Token-based API pricing; low-cost models are suitable for first-pass advisor answers and higher-cost models should be reserved for complex production reasoning.",
      "clientBillingTreatment": "Atelier operating cost unless a custom high-volume assistant is sold as a separate managed service.",
      "activationStatus": "not_connected_trial_safe"
    },
    {
      "provider": "Supabase",
      "purpose": "Durable database for leads, reports, advisor sessions, projects, support tickets, approvals, and ledger records.",
      "publicSource": "https://supabase.com/pricing",
      "currentReference": "Free tier exists for experiments; Pro is listed from $25/month with included database/auth/storage quotas and usage-based overages.",
      "clientBillingTreatment": "Atelier platform operating cost for Atelier CRM; client-owned app/database cost if the client receives a dedicated production portal.",
      "activationStatus": "env_required"
    },
    {
      "provider": "Vercel or equivalent host",
      "purpose": "Public website hosting, serverless API routes, previews, logs, analytics, spend controls, and deployment workflow.",
      "publicSource": "https://vercel.com/pricing",
      "currentReference": "Hobby starts free; Pro is listed at $20/month plus additional usage and spend-management features.",
      "clientBillingTreatment": "Paid directly by the client if client-owned hosting is selected, or included/managed under an Atelier care agreement if Atelier-managed hosting is selected.",
      "activationStatus": "host_decision_required"
    },
    {
      "provider": "2Checkout / Verifone candidate for standardized digital products; provider eligibility and activation require human approval. Studio services use separate contract and invoice rails (DID-016).",
      "purpose": "Checkout links, subscriptions, invoices/receipts, and VAT/sales-tax handling via the Merchant-of-Record.",
      "publicSource": "https://www.2checkout.com/",
      "currentReference": "Processor fees vary by country, card type, currency, and payment method; official pricing must be checked for the merchant region before activation.",
      "clientBillingTreatment": "Payment processor fees are third-party costs and are separate from Atelier build or care fees.",
      "activationStatus": "not_connected_live_approval_required"
    },
    {
      "provider": "Resend or equivalent email provider",
      "purpose": "Transactional email for intake confirmations, report delivery, status updates, and support notifications.",
      "publicSource": "https://resend.com/pricing",
      "currentReference": "Free and paid tiers exist; Pro is listed at $20/month with 50,000 emails/month and overage pricing.",
      "clientBillingTreatment": "Atelier operating cost for Atelier notifications; dedicated client email infrastructure is a client/provider cost.",
      "activationStatus": "not_connected_live_approval_required"
    },
    {
      "provider": "Twilio / WhatsApp Business Platform",
      "purpose": "Optional WhatsApp/SMS notifications after consent and template approval.",
      "publicSource": "https://www.twilio.com/en-us/whatsapp/pricing",
      "currentReference": "WhatsApp pricing combines Twilio per-message fees with Meta template fees; prices vary by country and template type.",
      "clientBillingTreatment": "Optional communication add-on; messaging fees are third-party costs and require consent/logging.",
      "activationStatus": "not_connected_live_approval_required"
    },
    {
      "provider": "Domain registrar / DNS provider",
      "purpose": "Domain registration, renewals, DNS records, SSL, and renewal protection.",
      "publicSource": "Registrar-specific live checkout required",
      "currentReference": "Exact domain availability and renewal prices require live registrar check; suggestions are branding strategy, not trademark clearance.",
      "clientBillingTreatment": "Paid directly by client to registrar whenever possible.",
      "activationStatus": "live_check_required"
    },
    {
      "provider": "ClickSites / builder platforms",
      "purpose": "Fast visual draft lane, optional builder-hosted site lane, and client-editable builder workflow where appropriate.",
      "publicSource": "https://clicksites.ai/",
      "currentReference": "Plan limits and export/publishing capabilities require live account verification before selling as a final delivery lane.",
      "clientBillingTreatment": "Either client-owned subscription or transparent pass-through/provider recommendation; Atelier build fee remains separate.",
      "activationStatus": "controlled_tool_lane_requires_account_review"
    }
  ],
  "implementationCompletenessChecklist": [
    "client-side advisor widget",
    "server-side advisor endpoint",
    "local fallback advisor",
    "durable advisor/session logging plan",
    "cost and provider disclosure model",
    "human escalation gates",
    "admin task visibility",
    "project request and quote draft workflow",
    "support ticket workflow",
    "launch kit and preview approval workflow",
    "blocked live actions until explicit approval"
  ],
  "nextActivationSequence": [
    "Configure durable storage and admin token.",
    "Add production rate limiting and bot protection on host.",
    "Add optional AI provider adapter behind budget and consent controls.",
    "Add payment provider in draft-only mode, then live only after explicit approval.",
    "Add email/messaging provider in draft-only mode, then live only after consent and approval.",
    "Add domain/hosting provider dry-run plans before any mutation.",
    "Run host readiness, security scan, smoke test, and receipt logging before public launch."
  ]
}