XO Notes

Private until you say
otherwise. Recorded either way.

Site observations, snag lists and decisions usually live in notebooks, camera rolls and personal spreadsheets, with no evidence chain and no record of who was shown what. By handover the story has holes in it. XO Notes keeps a record private by default, makes every disclosure a recorded act, and refuses to close an issue on somebody's word alone.

Private by default
Every disclosure recorded
Evidence-gated closure
Append-only and verifiable
Why It Matters

Disclosure is the recorded event

Of the platform's three C's, XO Notes speaks to Compliance, in the sense a private workbench can honestly claim: who was shown what, and when.

Privacy is the feature, not the setting

Most tools make everything shared or everything siloed. Here a record starts private and stays private until you deliberately share it, and the sharing itself is what gets written down.

An issue needs evidence and a second person

Resolution requires a typed resolution plus at least one piece of evidence the resolver can actually read, then verification by a different person. Four eyes, not one.

The history is append-only and verifiable

Notes, issues and decisions sit on an append-only, hash-chained history that can be verified. We say verifiable, not tamper-proof: verification is a command an operator runs, not a badge we award ourselves.

Outcomes

What a private workbench changes

Three outcomes taken from what the product does, not from what a brochure would like it to do.

01

Records start private, and every disclosure is recorded, with a report of who could see which revision and when.

02

Issues cannot close without readable evidence and verification by a second person.

03

A note becomes a Planner task with a provable link that never exposes the note.

Features

A workbench that keeps its own receipts

Notes, issues, decisions and meetings, each with the record of who saw what.

Private by default, shared on purpose

A note is visible only to you until you explicitly share it. Sharing is a deliberate act with a named recipient or team, and the act itself is recorded. The disclosure report reconstructs who could see which revision, and during which interval.

  • Person and team disclosureShare with a named person or a team, each share written to the record
  • A report of who could see whatReconstructs visibility by revision and interval, so the question is answerable months later
  • Disclosure is one-wayA share cannot be quietly taken back, so the record of what was seen survives
What the report does not say. It shows who could see a revision and when. It is an access history, not a read receipt, and it never claims anyone opened anything.
Disclosure history
Only youCreated 08 Jan 14:02, rev 1
A. WhitfieldPerson share, 09 Jan 09:30, rev 2
Facade package teamTeam share, 11 Jan 16:15, rev 3
Access history by revision, never a read receipt

An issue that cannot close on somebody's word

Raising an issue is easy. Closing one is deliberately not. Resolution needs a typed resolution and at least one piece of evidence the resolver can actually read, and then a different person has to verify it.

  • Evidence-gated resolutionA typed resolution plus readable evidence, or the issue stays open
  • Four-eyes verificationVerification is done by a different person from the one who resolved it
  • An append-only event logThe issue's history accumulates rather than being rewritten
Issue 0142 · closure gate
1Resolution typed by J. Okafor
2Evidence attached and readable
3Awaiting verification by a second person
The issue stays open until a different person verifies it

Decisions that keep their lineage

A decision is recorded with the person and the time. When it is later replaced, the new decision carries the supersession lineage, so the reasoning chain stays readable instead of being overwritten.

  • Recorded with person and timeThe decision register answers who decided, and when
  • Supersession lineageA replaced decision keeps its link to the one that replaced it
  • On the same evidential pipelineDecisions sit on the same append-only, verifiable history as notes and issues
Decision lineage
Bracket fixing centres at 600mm
A. Whitfield · 08 Jan · superseded
Bracket fixing centres at 450mm
A. Whitfield · 22 Jan · current

The meeting workbench, with XO Meet

Capture privately during the meeting, share with the attendees when you choose to, and return reviewed minutes to the meeting itself. Your working notes stay yours; what the room gets is what you decided to give it.

  • Private capture during the meetingNotes are yours while the discussion is still moving
  • Attendee-gated sharingShare to the people who were actually in the room
  • Reviewed minutes go back to the meetingThe meeting keeps the version that was reviewed, not the raw scribbles
A manual loop, deliberately. There is no transcript import and no notetaker feed. You write what you saw, and you decide what leaves your workbench.
Meeting workbench
1Capture privately while the meeting runs
2Share to attendees, recorded as a disclosure
3Reviewed minutes returned to the meeting

A note becomes a task without giving itself away

Promote a note into an XO Planner task and the link back is provable, but the note's content and identity never cross. At most a one-line attribution naming the author travels with the task, and the person promoting it can switch that off.

  • A provable link, not a copyThe task references the note without exposing it
  • Identity hygiene by defaultAt most a one-line attribution travels, and it can be turned off
  • Reporting that preserves visibilityXO Analytics reporting respects what each reader was allowed to see
Promotion to XO Planner
Note stays private
Cracked sealant, elevation B panel 14
Planner task
Inspect sealant, elevation B
The link is provable; the note's content never crosses
How It Connects

Where XO Notes sits in the platform

Each connection below is a documented workflow in the product, not an aspiration.

Meeting notes that stay yours until you share them

Capture privately during an XO Meet meeting, share to attendees as a recorded disclosure, and send reviewed minutes back to the meeting.

A note becomes a task without giving itself away

Promotion creates an XO Planner task with a provable link back. The note's content and identity stay behind.

Reporting that keeps private notes private

XO Analytics reporting respects the visibility of each record, so a dashboard never becomes a side door into someone's private workbench.

FAQ

Frequently asked questions

Can anyone see my notes?

No. A note is visible only to you until you explicitly share it, and every share is recorded.

Does the disclosure report show who read a note?

No. It shows who could see which revision and when. It never claims read receipts.

Can an issue be closed without evidence?

No. Resolution requires a typed resolution plus at least one piece of evidence the resolver can read, then verification by a different person.

Does the Planner task reveal my note?

No. The task links back provably, but the note's identity and content never cross. At most a one-line attribution naming the author travels with the task, and the promoter can switch it off.

Is the history tamper-proof?

It is append-only and hash-chained, and it can be verified. We say verifiable, not tamper-proof: verification is a command an operator runs.

Keep the record, keep it yours

See private capture, recorded disclosure and evidence-gated closure running against a project of your own.