Product requirements
What we're building, and why.
The living PRD for the Elora rebuild — consolidated from the platform overview, developer briefs and weekly calls. Internal reference; will move behind super-admin authentication.
What Elora is
Elora (formerly OnBrand) is an AI-powered brand-consistency platform. It acts as an active review layer that checks content against an organisation's own brand guidelines, messaging frameworks and compliance rules before publication — closing the consistency gap between the brand a company has defined and the content it actually ships.
Positioning
- Brand-first, not AI-model-first: Elora starts with the brand's own guidelines as the sole source of truth, then checks content against them. Competitors optimise content for AI models, risking off-brand messaging; Elora ensures content is on-brand first, then optimised.
- It is a brand intelligence and governance tool — explicitly not a grammar checker.
- Target market: regulated industries (financial services, insurance, healthcare) where off-brand claims carry reputational and commercial risk.
- The brand must project a serious, enterprise-ready image — modern but trustworthy (Monzo cited as the model).
Core value
- Protects investment: catches inconsistencies early, avoiding costly rework.
- Mitigates risk: prevents reputational and commercial harm from off-brand or non-compliant claims.
- Drives growth: consistent messaging builds trust and reinforces AI-search visibility signals.
Users & roles
Roles
- Super admin (Elora team) — platform-level access, audit logs, support and troubleshooting.
- Brand / organisation admin — manages guidelines, users, approval setup, billing and settings for their organisation.
- Contributor — uploads content, runs brand checks, applies fixes, submits for review.
- Approver — reviews and approves content within the approval workflow (post-launch phase).
Rules
- One organisation must never see another organisation's content, brands, documents, campaigns, users or check results.
- Settings entry point lives in the user profile menu (top-right) and is visible to organisation admins only.
- MFA available to all users; sessions expire after 30 minutes of inactivity (5-minute warning dialog), with an absolute 8-hour cap.
- Users are invited by secure link rather than an emailed password; password reset is token-based via email.
- A super admin can assign an alternative super admin; brand workspaces are allocated by the super admin with a visible counter of used versus available workspaces.
Core modules
Dashboard
- Organisation usage (brand checks this billing period, e.g. 65/100) with a visible progress bar.
- Your brands with per-brand alignment status; recent content with Review Ready status.
- Accurate check counting — increments on every successful AI analysis.
- Content insights: checks run this month broken down by finding category (Language, Messaging, Brand, GEO keywords), filterable by a custom date range.
- Filter and search across brands.
- Alignment is presented as a review state — pieces aligned versus findings outstanding — not as a graded brand score.
- Open decision (Miro board): remove 'Your brands' from the homepage view and rename 'Recent content' to 'Your content'. Held for confirmation with Becky — multi-brand switching is core, so the current mockup keeps both.
Brand setup & guidelines
- Upload brand guidelines, messaging frameworks and compliance rules as PDF, DOCX, DOC, TXT or MD (max 25MB, server-side validated).
- AI gap analysis on upload — identifies missing or weak areas in the guideline set.
- Document currency review and guideline management live in Settings.
- Onboarding questionnaire fills the gaps the uploaded guidelines leave — only asks about areas the documents do not already cover, and takes no longer than 30 minutes.
- Questionnaire disclaimer: Elora aligns content against the guidelines you set. We capture what you provide, we don't write or approve — answers must reflect the brand's current, agreed position.
Content Brand Check
- The core flow: upload/paste content → run check → review findings → apply fixes → export.
- Two-pane review: formatted content preview on the left, finding cards on the right.
- Content preview preserves original formatting (headings, lists, bold, italics, line breaks) and is editable in place.
- Content types: Financial Promotion, Social Post, Product Guide, ESG Report, Press Release, Whitepaper, Email/Newsletter, Website/Landing Page, Customer Communication, Blog/Article, Ad Copy, Video Script, Brief, Other.
Campaigns
- Group content pieces into campaigns with a campaign brief; track approval progress per campaign.
- Campaign brief alignment — content checked against the brief as well as brand guidelines.
Usage analytics
- Organisation limit with progress (checks used this period) and a per-brand breakdown.
Settings & billing
- Stripe billing: 14-day trial, tiered plans, vouchers, self-service customer portal, invoicing.
- 30-day data retention after cancellation, then full deletion.
- Transactional email via Postmark, branded (magic links, invitations, review notifications, receipts).
The AI Brand Check
Findings (the platform's term for flagged issues) are organised into four categories, each with its own flag colour. The uploaded guidelines are the sole source of truth — the AI must never invent rules.
The four categories
- Language — word choice: hype, vagueness, jargon and filler; preferred terminology and naming used consistently.
- Messaging — claims and promises the guidelines do not support; missing or conflicting strategic messages.
- Brand — tone and voice drifting from the brand guidelines; content that doesn't feel like the brand.
- GEO keywords — search and AI-visibility terms missing, weak or overused.
Recommendation behaviour
- Every recommendation explains: what was identified, why it matters for the brand, the supporting evidence from the guidelines, and the suggested action.
- Recommendations are decisive — 'Change X to Y', never hedged ('if title case is acceptable…').
- Where wording differs but meaning is preserved, show the preferred language and ask whether the variation was intentional.
- Source references must cite the correct guideline document, section and page.
- Guideline interpretation uses the strongest, most consistent evidence across documents — never cover pages, headers/footers, formatting, or isolated examples.
What the AI must not do
- No generic grammar, punctuation or readability suggestions unless the guidelines support them.
- No invented brand rules; no preventative checks for things absent from the content (except required elements like disclaimers).
- No self-contradicting findings — a recommendation saying 'no change needed' is filtered out post-processing.
- Flag every instance of an issue, not just the first occurrence.
Fixes
- Structured fix objects: replace, insert, or remove — all three types supported.
- Applied fix text always exactly matches the recommendation shown on the finding card (generated together, never separately).
- Fixes can be applied per instance; the preview remains manually editable after applying.
Consistency guarantees
The single most important product requirement. The brand check must be deterministic and comprehensive — three principles guide every decision.
The three principles
- First check catches everything — no finding may appear on a recheck that wasn't caught the first time.
- Same content, same results — identical input produces identical findings every time (temperature 0, structured prompting, hash-based result caching).
- Resolved content passes — a recheck verifies that flagged findings are resolved rather than running a fresh analysis that finds different things.
Content flow
The launch flow
- Upload → content check → fix findings → download. The approval workflow is built but hidden behind a feature flag for launch.
- Checks on typical content (500–1,500 words) complete in under 30 seconds, with a visible progress indicator (not a spinner).
- Word export (.docx) — clean version and version with comments — preserves headings, bullets, bold, italics and paragraph structure, ready for tracked changes in Word.
- Send for Review — email the clean version to one or more reviewers: branded email with logo, content title, submitter name, date, and the line 'This content has been pre-checked by Elora.' No scores or finding details included.
UX rules from trials
Findings display
- Findings are marked with colour-coded highlights in the content (not underlines); each highlight matches its finding card colour exactly.
- No severity labels (High/Medium/Low) — all findings need resolving before sign-off, so ranking is noise.
- After a fix is applied or a finding is resolved, the highlight turns green and stays visible so users can review what changed.
- Resolved finding cards collapse to a single-line summary (category icon, short title, green tick) so the two-pane workflow survives long finding lists.
- Resolve reasons: applied suggested fix, fixed manually, not applicable to this content, intentional brand decision, or not an issue (free-text explanation, recorded in the audit trail — likely signals the AI was incorrect).
- A final check runs at the end over manually amended text only — it must never raise new findings on text the user already resolved.
Sessions
- 30-minute inactivity logout; any activity resets the timer; active users are never logged out mid-task.
- Warning dialog at 25 minutes: 'You'll be signed out in 5 minutes due to inactivity. Stay signed in?'
- Absolute session cap of 8 hours regardless of activity.
Security & GDPR
Security
- Row-level security scoping every query to the authenticated user's organisation; complete data isolation between organisations and between brands.
- Authorisation on every endpoint with IDOR protection — changing an ID in a URL must never return another organisation's data.
- Bcrypt/argon2 password hashing, rate-limited login with lockout, MFA, session expiry.
- Input sanitisation (parameterised queries, XSS escaping) and server-side file validation (type, size, content).
- Encryption in transit (TLS) and at rest; uploaded documents accessible only within the owning organisation.
- Audit logging: logins, content submissions, brand checks, resolutions, document uploads/deletions, user changes — platform admin only.
GDPR & data protection
- Customer content and guidelines are used only to run brand checks — never used to train models, never shared with third parties.
- AI API tier documented and verified as non-retaining, non-training.
- UK/EU data residency documented for regulated-industry prospects.
- Full account deletion on cancellation (after 30-day retention); data export on request; cookie consent banner if non-essential cookies are used.
- Terms of Service accepted at registration; ToS and Privacy Policy linked in the footer.
Billing
Stripe integration
- 14-day free trial on sign-up with card details captured at registration; first charge on day 15.
- Trial-ending email 48 hours before the trial expires; abandoned-basket, completed-purchase and monthly analytics emails.
- Voucher / promo codes so clients can be onboarded without card details, with manual invoicing where a customer cannot pay by card.
- Agency pricing: £350/month for 3+ brands. Three brand workspaces included, allocated by the super admin; additional workspaces charged pro rata to the card, self-service.
- Tiered plans by brand-check volume.
- Self-service customer portal for plan changes, invoices and payment methods.
- Voucher/promo code support for trials and partner offers.
- Usage limits enforced per billing period with the dashboard counter as the visible source of truth.
- On cancellation: 30-day data retention, then deletion; dunning emails via Postmark.
Feature flags & later phases
Built but hidden at launch
- Approval workflow — in-platform review and approval; returns post-launch.
- Footnotes — hidden until content-type awareness is reliable.
- Related-document attachment (Brief Alignment) — hidden until figure/stat mismatch detection is trustworthy.
Future considerations
- Per-organisation configurable session timeout.
- Audit log visibility extended to organisation admins.
- Lead-gen 'Brand Alignment Gap' report as a viewable, non-downloadable webpage.
- Compliance as a fifth finding category (would need a fifth flag colour outside the approved palette).
- Campaign key messages as an additional review layer alongside brand guidelines.
- Google Docs integration — push content straight into Elora for review.
Decisions log
Agreed decisions
- Rebrand: OnBrand → Elora; trademark application pending (2-month objection window from early September 2026); interim development on a temporary subdomain.
- Terminology: 'Issues' → 'Findings'; 'Writing' category → 'Copy' where referenced; 'Feedback' → 'Findings'.
- Terminology: 'Approval readiness alignment' → 'Brand Alignment Review'; 'Resolve N issues to approve' → 'Resolve N findings to align'; 'Mark as approved' → 'Mark as aligned'.
- Severity labels (High / Medium / Low) replaced by the four finding categories.
- Fourth finding category is GEO keywords, not Compliance. The Miro board lists Compliance; it predates the trial calls and the approved flag palette, so GEO stands. Logged so it can be re-raised.
- Findings marked with highlights, not underlines; severity labels removed.
- Branding: 'Thread' concept approved; warm orange palette; gradients as accents only; enterprise-ready, not 'startup vibe'.
- AI strategy: hybrid model approach — low-cost model for document parsing, higher-quality model for content analysis.
- First client demo targeted for 6–7 October 2026.
Out of scope
Not included
- Trademark registration and legal counsel.
- Writing Terms of Service / Privacy Policy content (client provides; platform links and captures acceptance).
- New feature development beyond the agreed scope post-launch.
- Third-party service outages (AI providers, Stripe, email delivery).