# GeoIntel v1.0.0 Known Limitations ## Release position These limitations are explicit, bounded and non-deceptive. None is a hidden CRITICAL or HIGH release defect. Coverage and capability responses remain the runtime source of truth. - The access gate intentionally supports one environment-configured operator account. There is no registration, password-recovery email, role model, organisation management or multi-user database. Password rotation is an operator configuration action followed by a runtime restart. ## Source coverage - National administrative land and maritime scope is operational from persisted NGI/RBINS editions. Detailed themes are federated by jurisdiction; an operational Flemish source does not imply equivalent Walloon or Brussels coverage. - Land cover remains source-correct by jurisdiction: WALOUS 2018/2020/2023 covers Wallonia, Flemish products cover Flanders and UrbIS Land Cover covers Brussels. GeoIntel does not relabel WALOUS as a national source or silently merge incompatible regional legends. - Buildings, population, terrain, imagery, nature, agriculture, soil and flood themes may report `partial`, `not_configured` or `unsupported` outside the materialized source partitions. The UI and exports retain that state. - Belgian North Sea planning/reporting boundaries are materialized. Bounded strict-TLS MDK WCS acquisition is implemented but stays disabled until the operator enables `MDK_BATHYMETRY_ACQUISITION_ENABLED` with a coverage id that the live readiness probe advertises. Until then the theme reports `not_configured`; VHA profile observations are not presented as a seabed model or water volume. - Official endpoints can be temporarily unavailable. Bounded acquisition fails closed and never substitutes fixture or fabricated production data. ## Selection semantics - Coverage resolution currently accepts an EPSG:4326 rectangle. A rectangle around an irregular municipality or region can include land across a border or adjacent sea, so `outside_supported_scope` can be true even when the underlying named Area itself is wholly valid. - Cross-region and land/sea selections stay split by legal/source zone. Semantically incompatible metrics are not merged. ## Historical analysis - Historical comparison requires compatible source editions, units, coverage and observation periods. Sources without a governed series correctly return no comparable time series. - The RC10 storage audit reports 224 unavailable historical manifest intermediates from prior operator runs. There are zero missing current database artifact references; the historical paths remain visible as provenance warnings and are protected from cleanup inference. ## AI - The configured local YOLO model is opt-in, building-focused and bounded by its documented operator evidence. It is not claimed to be an optimally trained general model for all Belgian objects or themes. The capability API exposes this as `nationally_validated=false`, `validated_regions` and an explicit validation scope; operator review remains required. - PyTorch and Ultralytics are present only in the AI image. No model weights auto-download. A missing local model reports unavailable. - Local YOLO-seg and SAM segmentation are implemented through the ultralytics interface but stay `not_configured` until the operator points `YOLO_SEG_MODEL_PATH`/`SAM_MODEL_PATH` to existing local weights and enables them explicitly. GeoIntel never downloads segmentation weights automatically; fixture segmentation remains explicit-only. ## Operations - Long AI/GIS work still uses the existing synchronous job abstraction rather than a distributed durable queue. Interrupted synchronous work is marked failed on restart and must be retried explicitly. - GeoIntel RC is a controlled single-operator deployment. Authentication, multi-user authorization and tenant isolation are outside the frozen RC scope. - Cleanup remains manual, dry-run-first and confirmation-gated. No automatic retention schedule is installed.