What works now and what is next
The self-serve review works now. This table shows what is ready and what still needs setup before connected-account production. The live column is read from this deployment's configuration when the page loads.
| Capability | Status | Next step | Live signal |
|---|---|---|---|
| Guest self-audit | Code ready | Receipt paste, conservative PDF/CSV import, manual fallback, separate-currency totals, and proof-backed first action. | Not gated. The review runs in the browser tab without a server dependency. |
| Signed-in persistence | Code ready; deployment required | Activate PostgreSQL, session secret, token-vault key, identity provider, backups, retention, and shared rate limiting. | Session signing and the token vault are active; a backup restore drill is not yet recorded. |
| Assisted audit payment | Provider and legal gate | Apply migration 0016; complete qualified legal review, Razorpay KYC/configuration, signed webhook, replay, refund, and reconciliation proof. | Held behind the legal and provider gate; checkout stays hidden until settlement proof exists. |
| Gmail receipt sync | Google approval gate | Complete restricted-scope verification and prove consent, sync, resync, disconnect, deletion, and support. | Google's restricted-scope review is not complete, so the Gmail rail stays gated. |
| Bank, UPI, and card mandates | Partner and legal gate | No direct access is offered until approved regulated partner paths and production consent are proven. | No regulated partner rail is engaged; Vognary offers no direct bank, UPI, or card-mandate access. |