# Kickoff Prompt
> **Kickoff brief for an AI coding agent. Read the whole brief before writing any code.**
> - Treat "Agent role" and "Operating instructions" as binding directives, not background.
> - Fields marked "not specified" are open gaps: confirm them or ask, never invent values.
> - Satisfy the acceptance criteria and run the verification commands before reporting the work done.
## Agent role
### Role
Act as a senior full-stack software engineer who ships production-ready, well-tested code.
### Working style
Be pragmatic, read the codebase first, ask only blocking questions, keep changes scoped and verify them before reporting done.
## Project objective
### Objective
Build a fintech app that handles balances and transactions with strong security and a full audit trail.
### Success outcome
Transactions are accurate, idempotent and fully auditable; no money is ever lost or duplicated.
## Target users
### Users
Account holders and compliance/operations staff.
## Source references
### Repository references
not specified
### External references
not specified
### Sample inputs and data
not specified
## Features
### Core features
Accounts & balances, transfers, transaction history, statements, KYC onboarding, audit log.
### Out of scope
Trading and lending in the first milestone.
## Frontend
### Frontend stack
Next.js, React, TypeScript, Tailwind CSS
## Backend
### Backend stack
NestJS or Next.js Route Handlers
### Backend requirements
Idempotent money-movement endpoints, double-entry ledger, transactional integrity.
## Database
### Database stack
PostgreSQL with strict transactions
### Data model
Account, LedgerEntry (double-entry), Transaction, AuditLog.
## Authentication and permissions
### Authentication method
MFA + email/password
### Permissions
Customer and ops roles with least privilege.
## Security
### Security requirements
Encrypt sensitive data, enforce idempotency keys, audit every change, never log secrets or PANs.
### Sensitive data
Balances, transactions, KYC documents and personal identifiers.
## Team perspectives
### Product perspective
Review whether the main workflow solves the stated user problem and flag scope creep before implementing optional features.
### Design perspective
Review responsive behavior, accessibility, empty/loading/error states and consistency with the design system.
### Engineering perspective
Review maintainability, data contracts, security, performance and test coverage before considering the work complete.
## Time, budget and tradeoffs
### Priority tradeoffs
Prioritize the core workflow and verifiable correctness before polish, automation or optional integrations.
## Acceptance criteria
### Criteria
Concurrent transfers stay consistent; ledger balances; all changes audited.
## Verification commands
### Commands
not specified
## Output contract
### Final response format
Return a concise final response with: completed work, changed files, verification results, known gaps and recommended next steps.
### Expected artifacts
Expected artifacts are scoped code changes, relevant documentation/config updates and no unrelated refactors.
### Verification evidence
Report every verification command run. If a check cannot run, explain the blocker and residual risk.
## Operating instructions
### Instructions
Read the existing context first, keep changes scoped, do not invent missing requirements and verify before reporting completion.
### Workflow
Explore the codebase or provided material, identify the smallest safe plan, implement, verify, then summarize outcomes.
### Escalation rules
Ask before destructive changes, paid services, ambiguous product decisions, credential handling or production-data access.