- Add docs/references/SDM120-Modbus-Protocol.md extracted from the SDM120 PDF - M4 login hardening: brute-force exponential backoff, CLI escape hatch (reset-password/unlock/disable-totp), optional TOTP 2FA - M5 IoT/energy: Modbus-TCP SDM120 polling + energy tables, MQTT/HA Discovery expose framework, frontend sidebar + energy view - Add manual acceptance walkthroughs (M4 lock/unlock; M5 energy_cli read) - Index both milestones in docs/design/README.md
- roadmap.md: M1 (DB consolidation) -> M2 (React SPA) -> M3 (token/mobile) - docs/design/: agent-pipeline design docs with atomic tasks for M1-M3 - CLAUDE.md: workflow, doc map, commit conventions, review-notes briefing flow - .gitignore: ignore local review-notes/