§ masterplan.md
Human Rights Timeline
A scrolling storytelling timeline of local human-rights milestones with photos, documents and audio clips.
01
App overview and objectives
A documentation platform for human rights violations: a verified incident timeline, an evidence archive with chain of custody, testimony, and a campaign layer that turns records into pressure.
02
The problem worth solving
Evidence scattered across social media disappears and cannot be used later. A rigorous, preserved archive with verification standards is what makes accountability possible years afterwards.
03
Target audience
- Primary — Human rights organisations and investigative journalists.
- Secondary — Legal teams, researchers and the affected public.
04
Roles and permissions
- Visitor — read-only public pages, can sign up.
- Member — owns their own records, cannot see other users' data.
05
Core features
- Incident records with date, location, type, and verification status
- Evidence archive storing original files with hashes and provenance metadata
- Timeline and map views with filtering
- Testimony collection with consent and protection settings
- Verification workflow requiring multiple independent sources
- Campaign pages assembling verified records into a public case
Deliberately later
- Secure submission for at-risk contributors
- Multi-organisation federation
- Export packs for legal filings
06
Technical stack
React front end, Postgres for structured records, write-once object storage for evidence, hashing at ingest.
Why: Evidentiary value depends on immutability and provenance — hash on arrival, never modify originals, log every access.
Alternatives: General case-management software (mature, not built for public campaigning) or a spreadsheet and drive (immediate, useless in court).
07
Conceptual data model
Incident — date, location, category, summary, verification status, severity
Evidence — incident, file hash, type, source, captured_at, chain-of-custody log
Testimony — incident, witness reference, statement, consent scope, protection level
Verification — incident, verifier, method, sources, decision, date
Campaign — title, incidents included, demands, updates
08
Integrations
- Immutable object storage
- Geocoding
- Secure file intake
- Optional distributed timestamping
09
UI design principles
- Scroll is the narrative device: each section reveals one beat of the story.
- Full-bleed imagery alternating with quiet text-only moments to let the reader breathe.
- Always offer a skip-to-summary path for readers who want the facts fast.
10
Security considerations
- Witness identity is life-critical: separate identity from testimony, encrypt with restricted keys, and support fully anonymous records.
- Access logging on every evidence view, with role-based restriction and periodic review.
- Threat-model for state-level adversaries: minimise metadata, avoid third-party scripts, support access over privacy networks.
11
Development phases
Phase 1 — Prove the core
- — Incident records with date, location, type, and verification status
- — Evidence archive storing original files with hashes and provenance metadata
- — Timeline and map views with filtering
- — Static content and design system in place
- — Basic analytics
Phase 2 — Make it real
- — Testimony collection with consent and protection settings
- — Verification workflow requiring multiple independent sources
- — Campaign pages assembling verified records into a public case
- — Accounts, sign-in and password reset
- — Empty, loading and error states everywhere
Phase 3 — Polish and launch
- — Performance, accessibility and SEO pass
- — Legal pages, contact route and 404 handling
- — Wire up: Immutable object storage
- — Wire up: Geocoding
Phase 4 — Grow
- — Secure submission for at-risk contributors
- — Multi-organisation federation
- — Export packs for legal filings
12
Challenges and solutions
Risk — Publishing unverified claims damages the whole archive
Solution — Nothing public without two independent sources and a recorded verification decision.
Risk — Contributors are endangered by metadata
Solution — Strip EXIF at ingest while preserving the original in restricted storage for verification.
Risk — Platform takedown or seizure
Solution — Mirrored storage across jurisdictions and regular encrypted offline backups held by partners.
13
Future expansion
- Legal filing integrations
- Automated open-source verification assistance
- Regional partner deployments
14
Page list (13 pages)
- 01 PUBLIC Timeline — Verified incidents in order.
- 02 PUBLIC Evidence — Archive with provenance.
- 03 PUBLIC Testimony — Protected first-hand accounts.
- 04 PUBLIC Campaigns — Cases assembled for pressure.
- 05 PUBLIC Methodology — Verification standards, published.
- 06 AUTH Sign up — Create an account with email or a social provider.
- 07 AUTH Log in — Return to the account, with error and lockout states.
- 08 AUTH Reset password — Request a reset link and set a new password.
- 09 APP (signed in) Account settings — Profile, email, password, language and delete account.
- 10 PUBLIC Contact — Contact form plus real address, phone and email.
- 11 LEGAL & SYSTEM Privacy policy — What data is collected, why, and how to remove it.
- 12 LEGAL & SYSTEM Terms of service — Rules of use, liability and account termination.
- 13 LEGAL & SYSTEM 404 not found — Friendly dead end with search and links back.
15
Page map
PUBLIC AUTH APP (signed in) LEGAL & SYSTEM ────────────── ───────────────── ─────────────────── ─────────────────── ├─ Timeline ├─ Sign up └─ Account settings ├─ Privacy policy ├─ Evidence ├─ Log in ├─ Terms of service ├─ Testimony └─ Reset password └─ 404 not found ├─ Campaigns ├─ Methodology └─ Contact key flows: Timeline ──▶ Evidence Timeline ──▶ Testimony Evidence ──▶ Campaigns Methodology ──▶ Timeline
