Hyvara AI
June 17, 2026
SDR Hive v0.5.0 — Session 9
End of Day Readout — Design Partner Sprint

What we built.
Why it matters.

Design partner feedback from Colin Schap at Ensemble translated into shipped product — same day. Here's what changed, what it unlocks, and what's coming next.

23
Features shipped today
3
Demo accounts live
v0.5.0
Release version
2
Platform docs produced
Shipped today — v0.5.0 + v0.5.x
Every item below went from zero to live on sdrhive.hyvara.ai in a single session.
Shipped
v0.5.0 — Identity
Role switcher + dynamic sidebar nav
Colin logs in as SDR, flips to Team Leader, flips to AE — sidebar nav changes for each role. Available roles stored per user, current role saved to profile.
Colin can demo all three personas from a single account without logging out
Shipped
v0.5.0 — Platform
Ensemble demo accounts
colin.ensemble, josh.ensemble, and admin.ensemble created at hyvara-demo.com. Roles, tiers, and profile rows all configured. Pattern established for Slalom and PwC.
Colin gets keys tonight — first live design partner session ready to go
Shipped
v0.5.x — Trust
Transcript validation gate
Hard block before analysis runs. AI classifies whether pasted content is a real sales conversation. Wrong content gets a polite amber pill — no count burn, no wasted analysis.
Free tier users don't lose one of their 10 analyses to an accidental paste
Shipped
v0.5.x — Persona
Brand AE vs Partner / SI selector
Two fundamentally different qualification motions now declared up front. Works pre-login on the landing page (localStorage) and post-login on the qualifier (DB persist). Persona rides the analysis payload.
Partner SDRs at Ensemble get coaching that understands SOW and co-sell context, not just software sales
Shipped
v0.5.x — Feedback Loop
In-app feedback → Linear
Feedback button in sidebar. Bug/Feature toggle. Dictation via mic. AI polish (✨). Loom/screenshot URL field. Submits directly to Linear team HYV with submitter label. Design partners never leave the app to report issues.
Colin's bugs land in Linear automatically — no Slack DMs, no lost feedback
Shipped
v0.5.x — Knowledge
Knowledge Base file upload
Drag-and-drop PDF/PPTX/DOCX upload for Product Spec, Competitive Intel, and Enablement. Files stored in Supabase Storage. Title, category, file type, size, and active/inactive toggle on each record.
Team can upload their actual battlecards and product decks — the private brain starts here
Shipped
v0.5.x — Coaching
Follow-ups redesign + coming soon
Progress rings on each follow-up card showing qualification score. Call count indicator. "Prep my call" replaces "Re-qualify." Coming Soon section previewing multi-call qualification for v0.6.
Colin sees the coaching vision tonight — not a placeholder, a product direction
Shipped
v0.5.x — Conversion
Trial nudge at 3 and 7 analyses
Soft dismissible banner at 3 analyses. Strong modal at 7 analyses. Neither fires for Pro or Team users. Calendar invite pattern for trial end. No wall — just well-timed friction.
Free-to-paid conversion has a runway now — users see the upgrade moment before they hit the wall
Shipped
v0.5.x — Profile
Brands represented + what I sell
Pill selector for 12 major brands (Adobe, Salesforce, Snowflake, etc.) plus + Other. Products sold free text field. Both saved to profile and available for downstream Knowledge Base filtering.
SDR profile now carries the context that makes Knowledge Base personalization possible
Design partner feedback — translated to product
Direct quotes and observations from Colin Schap (Ensemble), David Maloof (PreSales Advisory), and Andrae Middleton (Hyvara) — mapped to what we built or queued.

"Right now the tool feels like a report card. The SDR submits a transcript, AI produces a verdict, and the SDR reads their own exposure. I want it to feel like a coach asking questions — where the SDR fills their own gaps and the output reflects their own thinking."

— Colin Schap, Account Executive / Team Leader — Ensemble

"If you're storing API keys in a shared environment variable, one compromised integration exposes every user on the platform. Each key needs to live in the user's own row — isolated, protected by RLS, decrypted only within their session."

— David Maloof, Advisor — PreSales Advisory — Security & Integration Architecture

"Not every SDR needs to see technique checkboxes and unlock rows on day one. There should be a simple view that shows the methodology and the blend without the complexity — and an advanced view for those who want to go deeper. Let the user choose."

— Andrae Middleton, Co-Founder — Hyvara AI — Analysis Tuning UX
What Colin said What we built Status
SDR needs to see what gates are open before the follow-up call, not after Follow-ups redesign with progress rings, missing gate tags, and "Prep my call" CTA Shipped
After the follow-up call, blend both transcripts and show me where I moved Multi-call qualification architecture — v0.6 scoped and Coming Soon preview live v0.6
I'm a Team Leader at Ensemble — I need to see both the SDR view and the manager view Role switcher with SDR / AE / Team Leader toggle. colin.ensemble pre-configured with all three roles Shipped
Partner SDRs at Ensemble are qualifying SOWs and co-sell motions — not just software Persona selector: Brand AE vs Partner / SI. Rides the analysis payload into v0.6 prompt injection Shipped
SDRs should compete against their own score, not a rubric they don't understand Progress rings in Follow-ups. Score gamification and persistent score display queued for v0.8 v0.8
If switching to Hyvara is another step, small teams won't do it Background CRM scanner vs primary UI — architecture decision queued for v0.9 scoping Decision needed
The manager shouldn't see a struggling SDR's analysis before the SDR and AE agree on the handoff Volley / SDR-to-AE messaging gateway — v0.7 architecture with five SAL outcomes v0.7
Shared Granola API key is an architectural risk — one key for all users is not acceptable at scale Edge function rebuilt as per-user. granola_api_key stored per user row under RLS. Pattern applied to all future integrations. Shipped
New SDRs don't need technique checkboxes and unlock rows on day one — complexity kills adoption Simple / Advanced toggle added to Analysis Tuning and qualifier landing page. Preference saved to profile. Simple mode hides techniques, shows locked methods as conversion prompts. Shipped
User impact — what changed for the SDR
Every build item maps to a specific outcome for the person using the product daily.
🛡️
Trust
0 wasted
Analysis count no longer burns on junk input. Validation gate blocks non-sales content before the analysis runs.
🎯
Relevance
2 personas
Brand AE and Partner / SI coaching are now distinct. Partner SDRs at Ensemble get SOW-aware analysis, not generic BANT coaching.
📈
Progression
Visual score
Progress rings in Follow-ups show qualification score at a glance. SDR knows where they stand before picking up the phone.
🔁
Feedback loop
1 tap
In-app feedback button creates a Linear issue in seconds. Mic + AI polish means no typing required. Issues don't get lost.
🧠
Private brain
File upload
Knowledge Base now accepts real files — PDFs, decks, docs. The team's institutional knowledge lives in the product, not a shared drive.
Conversion
3 + 7
Free users see a soft nudge at 3 analyses and a stronger prompt at 7. The upgrade moment arrives before the wall, not at it.

"The earpiece in the anchor's ear. Hyvara is the AI voice coaching in real time — without getting in the way. Every build item today moves the product closer to that metaphor and further from a report card."

— Hyvara product positioning, Session 9
What's next — v0.6 through v0.9
Everything queued from today's session, sequenced in build order.
v0.5.0 + v0.5.x — Shipped today
Design partner foundation
  • Role switcher, dynamic nav, Ensemble demo accounts
  • Transcript validation gate, persona selector
  • In-app feedback → Linear, Knowledge Base file upload
  • Follow-ups redesign, trial nudges, brands represented
v0.7 — SDR to AE connection
The Volley
  • SDR to AE messaging gateway — dirty laundry protection
  • AE Lite email link — non-seated AEs can receive handoff briefs
  • Accept / reject / kickback with five SAL outcomes
  • Persona field passed into handoff payload and DCN thread context
v0.8 — Gamification
Score as motivation
  • Persistent score display in SDR view
  • Score progression across calls — first call to handoff-ready
  • Leaderboard visible to Team Leader role
  • Leader Console restructure — Team Dashboard / Managing Up / Team Ops
v0.9 — Architecture decision
CRM integration + platform mode
  • Background CRM scanner vs primary UI — decision required first
  • Google Sheets connector — pre-CRM call list bridge
  • Admin impersonation / View As
  • @hyvara/connections extracted from DCN as shared platform component
The platform vision — Connection Spine
What started as an SDR coaching tool is becoming something larger. Here's the architecture behind it.

"Think of it as LEGO. Each brick is complete. You can use a single brick. But the moment you connect two bricks, the structure becomes something more than the sum of its parts. The connection between an SDR Hive and an AE Hive is not a feature — it is a revenue relay. And the relay is the platform."

— Hyvara Platform Architecture, June 17, 2026
Live — v0.5.0
SDR Hive
Qualification coaching, framework scoring, knowledge base, handoffs. The first hive. Standalone value. Connection port ready for AE Lite in v0.7.
Design partner accounts live. Colin, Josh, Peter, David all in the system
Live — v0.4
DCN — Deal Collaboration Network
Brand AE to Partner AE co-sell intelligence. The Connections module was built here first. Contact to cash, cash to implementation, implementation to renewal.
Connections module is platform infrastructure — not a DCN-only feature
Roadmap — v1.0
AE Hive
Deal management, technical brief routing, SE volley. AE Lite receives handoffs from SDR Hive. Full thread management when the org is ready to connect the bricks.
Every SDR handoff to an AE Lite is a product demo — the conversion motion is built in
New — Established today
Persona as cross-hive identity
Brand or Partner declared once in SDR Hive. Travels through every handoff, every thread, into DCN context. By the time a deal reaches DCN, the system knows it's a partner-originated co-sell.
First piece of cross-hive identity in the platform. Set once, used everywhere
New — Established today
Hybrid Brain concept
Public Brain = AI's general sales knowledge. Private Brain = everything the team uploads to the Knowledge Base. The Prius dashboard — gas engine vs battery. When the private brain is rich, every analysis becomes proprietary.
The MUD — Meaningful, Unique, Defensible. No other tool has your specific knowledge
Architecture — Session 10
Leader Console restructure
Four contexts currently collapsed into one: Team Dashboard (looking down), Managing Up (looking up), Team Ops (onboarding/PIPs/reviews), Platform Config (badges/branding). Needs separation before v0.8.
Team Leaders can navigate to what they actually need without scrolling 11 tabs
Security & Trust — What we found and fixed
Identified and resolved during Session 9. Documented here for full transparency with advisors and design partners.

"If you're storing API keys in a shared environment variable, one compromised integration exposes every user on the platform. The fix is per-user isolation — each key lives in the user's own row, decrypted only when their session calls it."

— Security principle applied to Granola integration, Session 9
IDENTIFIED
Vulnerability — Granola API Key
Shared environment variable exposure
The Granola integration was using a single shared API key stored as a Supabase environment variable. Any user connecting Granola was effectively sharing one credential across the entire platform. A key rotation by one user — or a key leak — would affect all users simultaneously. No user data was accessed. The issue was architectural, not a breach.
Discovered during integration review — no external exposure confirmed
FIXED
Resolution — Per-User Key Isolation
Granola edge function rebuilt as per-user
The edge function was rebuilt to read each user's Granola API key from their own row in the testhive_leads table — not from a shared environment variable. The key is only decrypted and used within the authenticated user's session. No cross-user key access is possible under the new architecture. The granola_api_key column is protected by Supabase Row Level Security.
Each user's Granola connection is now fully isolated — one user's key cannot affect another
Architecture — Applied Going Forward
Integration security pattern established
All future third-party integrations (Fireflies, Fathom, Gong, Email) will follow the same per-user key pattern. No shared environment variables for user-facing API credentials. Each integration stores its key in the user's profile row under RLS. The Integrations page UI reflects this — users paste their own key, it is masked on display, and they can disconnect at any time.
Security pattern is now the default — not something bolted on after the fact
Security posture — current state
Row Level Security
All Supabase tables protected by RLS. Users can only read and write their own rows.
Per-user API key isolation
Granola and all future integrations store keys per user, not in shared env vars.
Google OAuth + password auth
No passwords stored in plain text. Supabase Auth handles all credential management.
Masked key display
API keys shown masked in the Integrations UI. Full value never exposed in the browser after save.
Edge function server-side only
All Anthropic API calls run server-side via Supabase edge functions. API key never exposed to the browser.
Penetration testing
Scheduled before enterprise accounts onboard. SOC 2 readiness assessment queued for v1.0.