Audit summary
How to read the percentages
Every capability is assessed across four equally weighted layers using the current source, registered routes, operations, persistence, configuration, and declared gates. This audit is not a manual production test of every workflow. The percentage does not measure popularity, absolute quality, adoption, or return on investment, and it is not calculated from file counts or closed tasks.
- 25% · InterfaceThe screen, page, or control through which a user accesses the capability.
- 25% · OperationThe application or API operation that executes the declared workflow.
- 25% · Data and controlPersistent data, permissions, audit, and isolation between accounts or websites.
- 25% · ActivationThe capability can be used in production and is not stopped by a global launch gate.
Built through the activation layer but stopped by a global gate.
Implemented; complete activation depends on connecting or configuring the required service.
Foundation or controlled availability without a general launch.
Complete and active within the declared scope.
Not launched; it should not be purchased or evaluated as a current capability.
Public experience and discovery
The surfaces through which people understand the platform, find professionals, and access public resources.
Bilingual public marketing websiteMasterMyLife's main pages are delivered in Romanian and English with dedicated navigation, language variants, and metadata.
- homepage and explainer pages
- professional solution and pricing
- canonical, hreflang, Open Graph, and structured data
- sitemap and robots.txt
Condition or remaining step: Live within the declared public scope.
Directories and discovery surfacesThe network can project eligible public resources into discovery experiences without guaranteeing equal distribution or traffic.
- public profiles
- Business Pages
- communities
- events
- articles and editorial categories
Condition or remaining step: Visibility depends on public status, eligibility, relevance, and user choices.
Public professional profile and Business PageA professional can present their identity, work, and resources through a public presence connected to the network.
- public profile
- professional page
- about and follower sections
- associated public content
Condition or remaining step: Publication and visibility remain under the page owner's control.
Articles, documents, photos, and clipsPublic content can be created, managed, and discovered under the same social identity.
- articles and editor
- documents
- photos and albums
- clips and media resources
Condition or remaining step: Social articles support creation, listing, detail, and deletion; later editing does not yet have the same complete workflow as publication on provider websites.
Search, hashtags, and saved itemsMembers can find content and retain resources for a later return.
- network search
- hashtag pages
- saved items
- indexable public routes where the audience permits
Condition or remaining step: Results respect each resource's visibility and status.
Automatic SEO and AEO publication and submissionWhen content is published, MML generates the technical infrastructure and submits eligible pages to search engines and AI agents without a separate action for every URL.
- canonical URL
- robots and sitemap
- metadata and structured data
- automatic exposure of published URLs to discovery systems
Condition or remaining step: Submission does not guarantee indexing, ranking, recommendation, or citation; each search engine or AI system makes that decision.
Account, identity, privacy, and safety
The capabilities that protect access, user choices, and data rights.
Registration, login, and sessionsThe platform has complete workflows for account access and redirection into the right experience.
- account creation
- login
- persistent sessions and revocation
- access recovery
- first login
Condition or remaining step: Live for the access methods and policies configured in the platform.
Login and linking through social providersMML has OAuth flows for authentication start, callback, identity linking, and connector administration.
- OAuth start and callback
- state and PKCE where applicable
- identity linking
- connector administration
Condition or remaining step: Each social provider requires valid external credentials and configured callback URLs.
OpenID identity and authorization between a website and the platformMML can securely connect social identity and access to professional websites through versioned authorization flows.
- OpenID Connect
- PKCE and nonce
- expiring codes and tokens
- revocation and audit
Condition or remaining step: Available for configured identity providers and clients.
18+ eligibility, profile, and personal settingsContractual access is limited to adults, while users can manage their profile and preferences.
- 18+ eligibility rule
- profile and display
- email and password
- notification preferences
- visibility and privacy
Condition or remaining step: MML is not intended for people under 18.
Data export and account closureUsers can initiate controlled workflows to receive their data and close their account.
- export request
- secure generation and download
- deletion request
- operational retry
- retention policies
Condition or remaining step: Execution retains data the platform must legitimately keep and removes or anonymizes the remainder according to policy.
Consent and tracking preferencesAnalytics, marketing, and relationship data are processed according to each person's recorded decisions.
- analytics consent
- marketing consent
- notification preferences
- consent purpose and history
Condition or remaining step: Legal configuration and disclosure copy remain explicit responsibilities of the relevant operators.
Reporting, support, and moderationMembers can ask for help or report abuse, while operators have surfaces for investigation and administration.
- support tickets and replies
- abuse reporting
- content and account moderation
- operational record
Condition or remaining step: Response time depends on operating policy; the capability does not promise instant resolution.
Multi-factor authenticationMFA enrollment and challenge are not part of the current delivery.
- MFA enrollment
- login challenge
- recovery codes
- device management
Condition or remaining step: A complete enrollment, recovery, and verification flow is required before this can be marked live.
Social network and communication
The relationships and interactions that can turn an isolated visit into an audience that voluntarily returns.
Feed, posts, and public conversationsMembers and pages can publish, comment, and continue conversations within the selected audience.
- timeline
- posts
- comments and replies
- likes and shares
- hashtags
Condition or remaining step: Feed distribution depends on relationships, status, and each post's visibility.
Friends, follows, and followersPeople can create explicit relationships with profiles and pages without automatic enrollment or following.
- friend requests
- friend lists
- profile follows
- Business Page follows
- followers
Condition or remaining step: Joining through an invitation does not automatically create a friendship or follow.
Block, unblock, and relationship protectionA member can block or unblock another user, and the restriction is enforced across relevant relationships and social surfaces.
- block
- unblock
- blocked-user list
- enforcement in feed, relationships, and privacy
Condition or remaining step: Blocking follows current visibility contracts and does not replace abuse reporting.
Following hashtagsMML can record the relationship between a member and a followed hashtag so that the topic can contribute to discovery.
- hashtag follow
- relationship persistence
- discovery eligibility
- complete list management — partial
Condition or remaining step: The audit did not identify complete UI management for every followed hashtag and the symmetrical unfollow operation.
Network invitationsA provider or member can send an invitation, and the recipient decides whether to accept and join the network.
- invitation link
- optional email or phone association
- controlled acceptance
- invitation status
Condition or remaining step: Acceptance confirms network entry; it does not transfer private CRM data or create an automatic follow.
Communities and groupsThe platform supports the creation and management of spaces built around shared interests.
- creation and administration
- members and roles
- group content
- settings and public presentation
Condition or remaining step: Community administration is available, but extended engagement for group posts does not yet match the main feed.
Business Pages and social eventsOrganizations and professionals can manage pages, audiences, and events connected to the network.
- page creation and administration
- followers
- event creation and administration
- public pages and settings
Condition or remaining step: Paid commercial events remain subject to the separate commerce gate.
Messages, chat rooms, and notificationsMembers can communicate directly and receive updates about relevant activity.
- direct messages
- chat rooms
- notification list
- preferences and read status
Condition or remaining step: External delivery depends on the channel and the person's preferences.
Stories, photos, clips, and mediaMedia formats have dedicated publication, storage, and administration workflows.
- stories
- photos
- clips
- media library
- processing and defaults
Condition or remaining step: Format and processing limits apply at upload.
Internal network ads and promotionThe platform includes surfaces for creating, managing, and reporting internal social ads.
- ad creation
- ad management
- reporting
- operations and moderation
Condition or remaining step: This module is separate from MML's pilot for advertising on external platforms.
Abuse reporting across every resource typeReporting is live for main-feed posts and page posts, but equivalent coverage does not yet exist for every social entity.
- feed reporting
- page-post reporting
- administrative queue
- universal coverage — partial
Condition or remaining step: Uniform workflows are still required for users, events, and group posts while preserving type-specific context and moderation.
Professional websites and publishing
The infrastructure through which a provider builds, publishes, and manages their own website on MML.
Website creation and activationA provider can start from the catalog, create a draft, verify readiness, and activate the public experience.
- starter catalog
- site draft
- readiness check
- initial publication
- activation and public URL
Condition or remaining step: Activating a custom domain may require DNS configuration.
Connecting a website to a Business PageThe interface can connect the provider website to the professional identity in the network and eligible social projections.
- Business Page selection
- shared public identity
- social projections
- end-to-end persistence — to be confirmed
Condition or remaining step: The surface and contract are present; the static audit did not confirm the complete persistence journey for the association.
Templates and presetsA website can start from controlled structures with content inventory and compatibility checks.
- template list and detail
- presets
- content inventory
- compatibility report
Condition or remaining step: A particular design's availability depends on the published catalog.
Visual editor and content managementThe provider can change supported pages and content without a code change for every update.
- visual editing
- pages and sections
- articles and resources
- preview before publication
Condition or remaining step: Custom functionality outside supported components may still require dedicated development.
Theme, preview, and controlled publicationDesign changes follow a separate draft, preview, publication, or discard cycle.
- theme draft
- preview
- publish
- discard
Condition or remaining step: Publication is explicit; a draft does not automatically alter the live website.
Template switching and rollbackMML keeps a controlled workflow for structure changes, content mapping, and returning to a previous version.
- create switch
- apply and preview
- publish
- rollback or cancel
- remap and restore
Condition or remaining step: Exploration and local actions exist, but the audit did not identify the complete server command for persistently applying a post-launch switch.
Custom domain and DNS configurationThe provider can retain their domain and connect it to MML website delivery.
- canonical domain
- DNS readiness
- DNS instructions and export
- certificate and public routing
Condition or remaining step: Correct DNS configuration is required; control-plane automation depends on the enabled Cloudflare integration.
Cloudflare ASSETS, CDN, and edge cachePublished resources are delivered through Cloudflare infrastructure, bringing cached files closer to visitors and reducing origin requests.
- ASSETS
- edge cache
- versioned publication artifacts
- media delivery through R2
Condition or remaining step: Final performance also depends on images, scripts, device, connection, and cache-hit rate.
Content and DNS exportThe provider can request and download exports needed for the portability of their digital asset.
- content export request
- retry
- secure download
- DNS export request and download
Condition or remaining step: The export follows the current contract's format and limits.
Member area for every websiteEach website can provide a separate member space authorized for the provider and purchased or granted resources.
- purchases
- courses and downloads
- replays and appointments
- invoices and subscriptions
- favorites
- entitlement control
Condition or remaining step: A website member account does not automatically create a social profile.
Forms, CRM, and contact data rights
The tools through which interest becomes a manageable relationship with context and consent.
Forms and responsesA provider can build, publish, and manage forms connected to the website and CRM.
- create and edit
- publish and archive
- submissions
- validated fields
- optional scored outcomes
Condition or remaining step: Fields and consents must be configured for the form's real purpose.
CRM contacts and historyMML keeps contacts and the provider–client relationship context in one operational register.
- contact list and detail
- create and update
- lifecycle
- purchase and activity history
Condition or remaining step: It is an operational CRM for provider–client relationships, not a declared replacement for every enterprise suite.
Notes, tags, custom fields, and consentThe team can organize relationships without parallel files and retain evidence of accepted purposes.
- notes
- tags
- custom fields
- consent preferences and history
Condition or remaining step: Access is restricted through website permissions.
Pipeline, tasks, and saved listsContacts can be followed through stages and operational actions rather than merely stored in an address book.
- pipeline and stages
- contact movement
- created, completed, or cancelled tasks
- saved lists
Condition or remaining step: Branched visual automation is a separate roadmap product.
CRM import and exportData can enter and leave through controlled workflows with validation and retained context.
- contact import
- validation
- contact export
- processing status and result
Condition or remaining step: The importer does not invent consent; evidence and purpose must exist in source data.
Export and erasure at the person's requestA provider can process access or erasure requests for commercial relationship data.
- export request
- retry and download
- erasure request
- audit and operational status
Condition or remaining step: Applicable legal retention may limit the erasure of certain records.
Catalog, commerce, and financial administration
Offer-management tools are live; money movement and provider billing are separated behind a fail-closed legal and fiscal gate.
Products, offers, and pricesA provider can build the commercial catalog and control offer lifecycle.
- products
- offers
- one-time or recurring prices
- publish, withdraw, and archive
Condition or remaining step: A published priced offer does not activate paid checkout while the gate is blocked.
WooCommerce importThe catalog can be imported through the WooCommerce REST API and reconciled into the MML model.
- source connection
- product and offer import
- identifier mapping
- import status and errors
Condition or remaining step: A valid WooCommerce URL and credentials supplied by the store owner are required.
Shipping and physical fulfilmentA provider can configure shipping and follow physical orders through supported operational states.
- shipping configuration
- fulfilment queue
- preparation and dispatch
- states and audit
Condition or remaining step: Collecting payment for an order remains blocked until commerce approval.
Promotions, coupons, and gift cardsThe catalog includes complete tools for promotional rules and customer value.
- promotions
- coupon lifecycle
- gift-card issuance
- activation, blocking, and adjustment
Condition or remaining step: Their application in a real payment depends on commerce activation.
Free access and entitlementsMML can grant and revoke resource access without a financial transaction.
- grant and revoke
- full or read-only access
- expiry and status
- member-area projection
Condition or remaining step: Access is separate from paid checkout and respects the source provider and website.
Free checkout and orders without paymentA free offer can pass through checkout, create an order, and grant access without a payment processor.
- public checkout
- free order
- customer data and consent
- digital fulfilment
- entitlement
Condition or remaining step: The flow respects limits, consent, and resource eligibility; it does not activate money payments.
Checkout, orders, and money paymentsThe interface, operations, and persistence exist, but payment launch is globally stopped until legal, fiscal, and privacy approval.
- checkout
- orders
- payment
- webhooks and reconciliation
- financial states and audit
Condition or remaining step: Current gate: blocked:legal-fiscal:v1. Approval of the Stripe Connect model, invoice policy, and data-protection roles is required.
Stripe Connect, refunds, and customer subscriptionsConnection, dashboard, refund, and subscription-change flows are implemented, but financial operations are not launched while the gate is blocked.
- connect and reconnect
- Stripe dashboard
- refund
- subscription change
- webhooks
Condition or remaining step: An approved gate and complete production Stripe secret group are required.
Invoices, credit notes, and SmartBillMML has flows for fiscal profiles, invoices, credit notes, and SmartBill integration, but commercial issuance remains blocked pending fiscal-policy approval.
- fiscal profile
- invoices
- credit notes
- SmartBill connect and retry
- fiscal exports
Condition or remaining step: Romanian numbering, VAT, credit-note, and retention rules must be approved.
Plans, subscriptions, and provider billingThe plan catalog, billing accounts, rebills, and provider documents are implemented, but commercial activation is fail-closed.
- plans and prices
- billing accounts
- provider subscriptions
- rebills
- invoices and commissions
Condition or remaining step: Current gate: blocked:legal-fiscal:v1; provider-billing approval is separate from commerce approval.
Paid social membership and walletContracts and surfaces for membership and wallet exist, but the capabilities are not activated in the current Worker composition.
- membership checkout
- wallet
- deposit and withdrawal
- transfers
- transactions
Condition or remaining step: Runtime capability registration and paid-commerce approval are required before financial workflows can be published as live.
Members, courses, events, bookings, and live delivery
The modules through which a professional delivers the service and retains progress in the same system.
Members and accessA provider can grant or revoke access and see the relationship between members and resources.
- member overview
- grant
- revoke
- entitlement and authorization
Condition or remaining step: Paid access depends on commerce; direct grants remain live.
Courses, lessons, enrollment, and progressCourses can be created, published, and delivered to members with progress retained in context.
- create and update
- publish and archive
- enrollment
- lessons and resources
- progress
Condition or remaining step: Selling a course for money is subject to the commerce gate.
Events, tickets, and attendeesA provider can manage the full operational lifecycle of an event.
- create, update, and publish
- ticket types
- waitlist
- transfer
- check-in and no-show
- cancellation
Condition or remaining step: Collecting payment for tickets is blocked together with paid commerce.
Services, availability, and appointmentsThe operational calendar includes resources, availability rules, and the complete appointment lifecycle.
- services and resources
- availability and closures
- booking
- rescheduling
- cancellation, completion, and no-show
Condition or remaining step: Appointment payment, where required, remains subject to the commerce gate.
Google Calendar, Microsoft Calendar, and Apple ICSAppointments can be synchronized or exported to supported calendars.
- connect and reconnect
- retry and disconnect
- Apple ICS export
- token create, rotate, and revoke
Condition or remaining step: Google and Microsoft require OAuth configuration; Apple uses an ICS feed and subscription token.
Webinars, live meetings, and recordingsA provider can create live sessions and synchronize meetings, attendance, and recordings.
- webinar creation and publication
- provider connection
- meeting and attendance synchronization
- recording registration, policy, and deletion
Condition or remaining step: External video capabilities require provider OAuth and configured recording policies.
Integrations, notifications, tracking, and analytics
The connectors and signals that link activity to communication and business decisions.
Transactional notifications and preferencesOperational events can generate notifications through configured channels while respecting user preferences.
- notification center
- preferences
- email delivery
- web push
- retry and status
Condition or remaining step: Email delivery depends on Brevo and production configuration.
CRM and audience synchronization with BrevoEligible contacts can be synchronized to Brevo based on consent, while Brevo remains an external service.
- connect, reconnect, and disconnect
- contact sync
- consent filtering
- retry and integration status
Condition or remaining step: Brevo connection and valid marketing consent are required; MML does not claim a complete native campaign editor.
OAuth connectors for external servicesTokens and connections for Google, Microsoft, and Zoom have a controlled connect, refresh, and recovery lifecycle.
- OAuth start and callback
- encrypted tokens
- refresh
- disconnect
- health and attention state
Condition or remaining step: Credentials and consent at the external provider are required.
Operational analytics and measured funnelsA provider can view the indicators and operational journeys available across business modules.
- analytics overview
- funnel
- operational indicators
- versioned events
Condition or remaining step: A measured funnel is not the same as the visual automation builder on the roadmap.
GA4 ecommerce, GTM, Meta Pixel, and domain verificationWebsites can enable approved scripts and GA4 ecommerce events according to consent.
- Google Analytics
- Google Tag Manager
- Meta Pixel
- Google, Bing, and Facebook verification
- ecommerce events
Condition or remaining step: Identifiers supplied by the provider and correct configuration in external accounts are required.
Server-side advertising tracking and CRM → Ads feedbackA complete flow that sends qualified CRM conversions back to advertising platforms is not available today.
- Meta Conversions API
- enhanced conversions
- browser-server deduplication
- qualified CRM conversions
Condition or remaining step: Event contracts, platform connections, deduplication, consent, and signal-quality monitoring are required.
Complete native email-campaign editorMML delivers notifications and synchronizes audiences with Brevo, but it does not currently provide a complete native marketing-campaign editor.
- email editor
- templates
- segments
- scheduling
- campaign reporting
Condition or remaining step: An editor, templates, segmentation, scheduling, reporting, and unsubscribe management within the same product are required.
Administration, operations, and infrastructure
The shared foundation that lets MML operate multiple websites, workflows, and data types without rebuilding per provider.
Central administration and operationsAuthorized operators have distinct collections for financial, social, content, support, and infrastructure administration.
- users, roles, and languages
- content and moderation
- support
- billing and reports
- jobs, webhooks, exports, and retention
Condition or remaining step: Each collection is role-protected; its existence does not grant access to ordinary users.
Administrative impersonation and reauthenticationAuthorized operators can use an audited impersonation flow, while sensitive operations may require reauthentication.
- start and stop impersonation
- actor context
- audit
- reauthentication for sensitive actions
Condition or remaining step: Access is restricted to administrators and does not remove the limits on protected operations.
Multi-tenancy, permissions, audit, and idempotencyBusiness operations are constrained by website, provider, and role, while sensitive mutations retain the necessary version and audit controls.
- site isolation
- provider and staff roles
- ownership transfer
- explicit permissions
- audit
- idempotency
- expected version and correlation ID
Condition or remaining step: Operational security also depends on correct role and secret administration.
CSRF, origin checks, rate limits, and TurnstileSensitive requests are checked through session-, actor-, and origin-bound controls with rate limiting and challenges where configured.
- CSRF
- origin validation
- rate limiting
- Turnstile
- authentication protection
Condition or remaining step: Turnstile and rate limiters depend on Worker bindings and deployment keys declared in configuration.
Granular global RBAC for operationsThe role catalog exists, but access to the global console relies mainly on the admin role rather than a final granular matrix for every collection.
- role catalog
- global admin role
- per-collection permissions — partial
- granular enforcement — partial
Condition or remaining step: Explicit global permissions must be applied consistently in UI, API, and audit for every operations family.
Separate D1 ownership for social and business dataSocial data and website, CRM, commerce, and operations data have separate ownership and forward-only migration ledgers.
- OPENSN_DB
- mastermylife-eu DB
- separate migrations
- declared query contracts and indexes
Condition or remaining step: Separation reduces ownership ambiguity; it is not an application-level backup promise.
R2 storage separated by asset typePublic media, private data, and website artifacts use distinct storage areas.
- media
- private storage
- site configuration
- site delivery
Condition or remaining step: Public or private access is determined by the delivery workflow, not merely by object existence.
Queues, DLQs, replay, and alertsSocial notifications, business jobs, and email each have declared queues and dead-letter queues with authenticated replay.
- three operational queues
- dedicated DLQ
- terminal observations
- replay
- Brevo alerts without payloads in logs
Condition or remaining step: Operator alerts and external delivery require configured production secrets.
Cron, leases, and controlled retryScheduled tasks are claimed by key and time without repeating completed tasks when a neighbouring task fails.
- four cron triggers
- lease
- retry for failed or expired work
- deduplication
- terminal alert
Condition or remaining step: One terminal operational alert is issued after three attempts.
Controlled release from GitHub to CloudflareProduction is built and published only from protected main with preflight, migrations, and authorization of the exact SHA.
- main-only
- resource and secret preflight
- ordered D1 migrations
- single deploy
- post-release evidence
Condition or remaining step: A push proves a Git update; live status depends on completion of the authorized Cloudflare workflow.
Application-level backup and restoreThe current delivery does not provide a contractual guarantee for complete application backup and restoration.
- versioned backup
- verified restoration
- retention
- RPO and RTO
- incident procedure
Condition or remaining step: An approved backup, retention, restoration, periodic testing, and RPO/RTO policy is required.
Product roadmap
Declared directions that must not be confused with capabilities available today.
Built-in AI for prompt-based creation and developmentThe intended journey is prompt → editable draft → human review → publication within the professional's page, program, and content context.
- page and article drafts
- program and lesson outlines
- FAQs and events
- adaptation and translation
- routine updates without a technical ticket
Condition or remaining step: Release date, models, limits, permissions, and commercial conditions have not yet been announced.
Mobile application based on the shared backendThe PRO direction is to reuse MML identity, content, access, and progress in a dedicated mobile experience.
- shared authentication
- content and access
- progress
- synchronization
- push notifications
Condition or remaining step: There is no public mobile release yet; the application, notifications, synchronization, and store-release processes are still required.
Visual funnel builder and branched automationMML measures journeys and has operational workflows, but it does not currently provide a complete visual editor for branching and automation.
- visual canvas
- conditions and branches
- triggers
- actions
- history and debugging
Condition or remaining step: The editor, rules, triggers, actions, versioning, and execution observability are required.
Advertising pilot with possible MML co-investmentFor selected professionals, MML may evaluate a pilot with an indicative budget of EUR 500–1,000 per month for testing.
- provider qualification
- test hypothesis and budget
- conversion measurement
- data-based continuation decision
Condition or remaining step: No operational product has been launched yet. The initiative will remain selective, subject to qualification and measurement, and will not guarantee clients, revenue, or profit.
Universal synchronization for external contentMML has specific imports and projections, but it does not provide a universal engine that synchronizes every content type from every external platform.
- generic connectors
- content mapping
- conflict resolution
- bidirectional synchronization
Condition or remaining step: Each source would require a data contract, conflict rules, ownership, scheduling, and observability.
Native MML video streamingLive sessions use external-provider integrations; MML does not currently operate its own video-streaming engine.
- video ingest
- transcoding
- adaptive streaming
- recording
- operations and moderation
Condition or remaining step: Ingest, transcoding, adaptive delivery, moderation, recording, and video-infrastructure operations are required.
See how the live capabilities come together into one system for your website, audience, and client relationships.
