The Rest of the Authorized Product
Once the phone owns a transport, administration still needs secrets, routes, and files. Those are later milestones, each with an acceptance list before implementation, none of them a license to copy every feature of another iOS terminal. Keychain-backed private keys, import and generation, passphrases, compatible algorithms, an explicit agent-forwarding policy, jump hosts, multiple hops with clear failures, configuration import that keeps secrets out of the shareable half. Then SFTP: a browser, Files integration, queues with progress and cancel, conflict review, no silent overwrite, no recursive delete as a default. Then the workday test: saved workspaces, gateway and direct coexisting, keyboard customization as justified, a compatibility matrix of real hosts, sustained daily acceptance. That last one is the bar again — absence of the other apps, not a settings count.
None of this is present tense. A Keychain screenshot in a lesson that says "you import a key" will fail the same review as a fake host-key dialog. Write them as destination. Keep today's "the phone does not receive private keys in continue-host-work" in the present, because that refusal is load-bearing until the key milestone actually ships.
Acceptance Before Implementation
Each milestone gets a concrete acceptance list first. That is how this family keeps a destination from becoming a vibe. "Jump hosts" is not done when a field exists. It is done when a named hop fails loudly, a secret does not leak into a log, and Dad can take the route he actually uses. "File transfer" is not done when a list of names draws. It is done when a conflict is a decision and a recursive delete is not a default.