Comprehensive PRD · 29/09/2026
FamiVanta OS is a secure, all-in-one family operating system that replaces fragmented household tools — calendars, chore charts, finance trackers, care logs, legacy planners, and location apps — with a single, unified platform. It is designed to manage a household's daily life, preserve multi-generational history, and build a lasting legacy.
To give every family a private, intelligent, and durable system of record that grows with them — from the first day of onboarding through to legacy handover — without the privacy compromises, fragmentation, or subscription sprawl of today's point solutions.
Family Foundation
Identity, members, relationships, governance
Household Operations
Tasks, calendar, meals, shopping, inventory
Finance
Transactions, budgets, assets, subscriptions
Care & Wellbeing
Care profiles, medications, health, habits
Legacy
Memories, oral history, time capsules, digital assets
Family Safety
Location sharing, safe zones, SOS, geofencing
Extended Family Network
Cross-household coordination, shared events, privacy-first sharing
FamiVanta OS targets UK families as the primary launch region, with British-centric data samples (UK locations, GBP currency, British-mixed demographics). Example families reflect diverse backgrounds — British, Asian, South American, and American — to represent modern UK households. The platform is designed to scale globally while respecting regional privacy expectations.
Persona 1: The Nuclear Family
Two parents and children sharing a household. Primary need: coordinated calendars, chore rotation, shared shopping lists, and a unified view of the week.
Persona 2: The Blended Family
Co-parenting across two households. Primary need: flexible custody schedules, separate privacy circles, and a neutral shared space for child-related coordination.
Persona 3: The Extended / Multigenerational Family
Grandparents, adult children, and grandchildren. Primary need: care profiles for elderly relatives, medication tracking, continuity planning, and legacy preservation.
Persona 4: The Plural / Chosen Family
Non-traditional family structures. Primary need: flexible member roles, custom relationship mapping, and inclusive identity configuration.
Every family member is assigned a role (admin or user) and a family role (spouse, parent, child, teenager, grandparent, extended family, caregiver). Age-based permissions gate features for minors, and parental controls can lock notification preferences and screen-time-sensitive settings.
FamiVanta OS is built on the Base44 platform-as-a-service, using a modular, domain-driven architecture. Each pillar maps to a set of entities, pages, and backend services with clear service boundaries.
| Layer | Technology | Description |
|---|---|---|
| Frontend | React + Vite + Tailwind CSS + shadcn/ui | 138 pages, lazy-loaded for fast initial render. Responsive hybrid desktop (deep planning) and mobile (quick coordination) interfaces. |
| Backend | Base44 serverless functions (Deno) | 7 deployed functions handling payments, emergency SOS, geofence logging, and notification delivery. |
| Database | Base44 managed MongoDB with Row-Level Security | 87 entities with per-record RLS rules scoping create, read, update, and delete operations. |
| Auth | Base44 Auth (email/password, Google OAuth, OTP) | Platform-owned auth backend with ProtectedRoute gating on authenticated routes. |
| Payments | Base44 Payments (Wix-powered) | Checkout, webhook-fulfilled subscription granting, and idempotent cancellation handling. |
| Realtime | Entity subscriptions (WebSocket) | Live updates for location pings, list items, and safety events. |
| Automation | Base44 Workflows (CNCF SWF) | 3 active entity-triggered workflows for meeting, task, and curriculum notifications. |
67 features across six pillars. Each feature is backed by a dedicated page, entity, or component in the codebase.
85 entities across 9 domains. Every entity includes built-in fields (id, created_date, updated_date, created_by_id) and is protected by Row-Level Security (RLS).
| Entity | Key Fields |
|---|---|
| Family | name, motto, mission, structure_type, primary_country, languages, faith_preference, setup_completed |
| Member | full_name, role, life_status, life_stage, email, phone, avatar, bio, birth_date |
| Relationship | from_member_id, to_member_id, relationship_type |
| User | id, email, full_name, role (admin/user), plan (subscription) |
| Constitution | title, clauses, version, ratified_date |
| ParentingPlan | title, custody_schedule, arrangements |
| Entity | Key Fields |
|---|---|
| Task | title, description, assigned_to, category, due_date, priority, status, recurrence, difficulty, reward, rotation_member_ids, approval_status, completion_history |
| CalendarEvent | title, date, time, type, attendees, recurrence, location |
| Meeting | title, date, time, meeting_type, attendees, agenda, status |
| MeetingDiscussionPoint | meeting_id, point, status, raised_by |
| MeetingFeedback | meeting_id, member_id, rating, dynamics_score, wellness_score, comment |
| Meal | name, date, meal_type, recipe_id, assigned_to |
| Recipe | title, ingredients, instructions, prep_time, servings |
| ShoppingItem | name, quantity, category, purchased, list_id |
| SharedList | name, category, member_ids, color |
| SharedListItem | list_id, name, quantity, completed, assigned_to |
| ListTemplate | name, category, default_items |
| InventoryItem | name, quantity, category, location, expiry_date |
| HomeRepair | title, description, status, cost, assigned_to |
| VehicleMaintenance | vehicle, service_type, date, mileage, cost |
| Pet | name, species, breed, birth_date, vet, vaccinations |
| Subscription | name, cost, billing_cycle, renewal_date, category |
| TimeSlotProposal | meeting_id, member_id, proposed_slots |
| Project | title, status, assigned_to, due_date, tasks |
| Entity | Key Fields |
|---|---|
| Transaction | amount, type (income/expense), category, date, member_id, account, recurrence, is_emergency_fund |
| Budget | category, limit, period, spent |
| Asset | name, type, value, owner_id, location |
| Base44Purchase | checkoutSessionId, status (pending/paid/canceled), appUserId, buyerEmail, productId, amount, currency, subscriptionId, paidAt |
| Entity | Key Fields |
|---|---|
| CareProfile | member_id, member_name, care_summary, emergency_contact, gp_clinician, mobility_note, communication_note, is_active |
| CareNote | care_profile_id, author, note |
| CareCircleMember | care_profile_id, name, role, phone, email, is_primary_carer, is_external |
| Medication | care_profile_id, medication_name, dosage, instructions, schedule_time, prescribing_clinician |
| ContinuityPlan | member_id, member_name, status (draft/active) |
| ContinuityRecord | continuity_plan_id, category (financial/property/legal/practical), title, notes, privacy_level |
| ContinuityHandoverItem | continuity_plan_id, continuity_record_id, record_title, record_category |
| ContinuityTrustedContact | continuity_plan_id, name, relationship, email, phone, status (nominated/active) |
| ContinuityRelease | continuity_plan_id, trusted_contact_id, status (active/revoked), activated_at |
| HealthRecord | member_id, type, provider, date, notes |
| WellnessRecord | member_id, mood, energy, notes, date |
| FitnessLog | member_id, activity, duration, date |
| Habit | name, member_id, category, frequency, target_count, completion_dates, current_streak, longest_streak |
| DailyPulse | member_id, date, mood, energy, sleep_hours |
| GrowthTracker | member_id, date, height, weight, notes |
| CurriculumProgress | child_name, band, module_number, track, status |
| Entity | Key Fields |
|---|---|
| LegacyPlan | member_id, status, details |
| LegacyTimeline | title, date, description, member_id |
| Memory | title, description, date, member_id, media |
| OralHistory | title, narrator, date, transcript, media |
| LifeEvent | title, date, category, description, member_id |
| Photo | title, url, album_id, date, member_id |
| Tradition | name, description, frequency, origin |
| TimeCapsule | title, open_date, contents, sealed_by |
| HeritageLocation | name, address, latitude, longitude, significance |
| Accomplishment | member_id, title, date, category |
| GiftRegistry | name, occasion, items, recipient |
| DigitalAsset | name, type, value, location, access_instructions |
| Entity | Key Fields |
|---|---|
| LocationShare | owner_id, owner_name, viewer_ids, sharing_mode (precise/approximate/journey_only/none), duration_type, started_at, expires_at, is_active, consent_acknowledged, managed_by_guardian |
| LocationPing | owner_id, owner_name, latitude, longitude, accuracy_meters, captured_at, share_id, sharing_mode |
| SafeZone | name, address, latitude, longitude, radius_meters, assigned_member_ids, alert_on_entry, alert_on_exit, viewer_member_ids, color, is_active |
| SafetyPreset | preset_type (routine/care/travel), name, member_ids, safe_zone_id, window_start, window_end, schedule_days, carer_member_ids, sharing_mode, status |
| SosEvent | triggered_by_id, triggered_by_name, latitude, longitude, accuracy_meters, location_label, recipient_member_ids, recipient_emails, email_delivery, notification_delivery, status (active/acknowledged/resolved) |
| SafetyAudit | event_type, resource_type, resource_id, action, result, user_name, risk_level, metadata |
| Entity | Key Fields |
|---|---|
| FamilyDecision | title, description, status, decision_type, voters |
| DecisionPoll | question, options, votes, closes_at |
| FamilyRating | member_id, category, rating, date |
| StrategyInitiative | title, description, status, owner, timeline |
| Notification | title, message, type, tier (routine/important/urgent/emergency), member_id, is_read, action_url, requires_acknowledgement, delivery_channels, family_circle |
| NotificationPreference | member_id, feature, family_circle, delivery_channels, routine/important/urgent/emergency_tier, quiet_hours, locked_screen_preview, is_parental_rule |
| WidgetConfiguration | member_id, widget_type, is_enabled, show_when_locked, selected_features, offline_action_queue |
| AuditLog | event_type, resource_type, resource_id, action, result, user_name, risk_level, metadata |
| Entity | Key Fields |
|---|---|
| ExtendedFamilyNetwork | network_name, description, owner_family_name, connected_family_names, connected_households, invite_code, status, max_families, plan_tier (extended/extended_plus) |
| NetworkSharedEvent | title, description, date, start_time, end_time, category, location, network_id, network_name, household_name, created_by_name |
| NetworkBudgetEntry | budget_name, household_name, network_id, network_name, category, planned_amount, actual_amount, currency, period_start, period_end, status |
| NetworkSharingPermission | network_id, source_family_name, target_family_name, sharing_type (directory/events/budget/reminders), is_enabled, enabled_by_name, enabled_at |
| NetworkConnectionRequest | network_id, requesting_family_name, target_family_name, feature_requested, message, status (pending/approved/rejected), requested_by_name |
| NetworkSharedReminder | network_id, source_family_name, target_family_name, reminder_type (birthday/anniversary/special_occasion), title, date, is_enabled |
| Entity | Key Fields |
|---|---|
| SharedContact | name, relationship, phone, email, category |
| EmergencyContact | name, relationship, phone, member_id, priority |
| EmergencyReadiness | checklist_items, status, last_reviewed |
| Travel | title, destination, start_date, end_date, members, itinerary |
| EducationRecord | member_id, institution, qualification, start_date, end_date |
| EducationalResource | title, category, url, description |
| KnowledgeBase | title, category, content, tags |
| SkillExchange | member_id, skill_offered, skill_wanted, description |
| VolunteerHub | opportunity, organisation, date, members |
7 deployed serverless functions (Deno runtime). All functions that handle user identity derive it from base44.auth.me() server-side — no request-supplied identity is trusted, preventing spoofing.
create-checkoutPublic (no login required)Resolves the product and its price server-side from a hardcoded catalogue (quarterly £37, bi-annual £67, annual £97), constructs a Wix checkout session, persists the checkoutSessionId on a pending Base44Purchase, and returns a redirectUrl. Validates quantity as a positive integer and fails closed if no server-owned app URL is available.
payments-webhookWebhook (JWT-verified, no user)Receives ORDER_APPROVED, SUBSCRIPTION_CANCELED, and SUBSCRIPTION_ENDED events. Verifies the RS256 JWT, resolves the pending Base44Purchase by checkoutSessionId, grants subscription access by setting the plan field on the User entity, sends a thank-you email, and marks the purchase paid. On cancellation/expire, revokes the plan. Idempotent on terminal statuses.
send-sosAuthenticated (base44.auth.me)Derives the caller's identity server-side from their Member record (never trusts request-supplied IDs). Creates an SosEvent with live location, creates in-app emergency notifications for all family members, sends email alerts, and writes an audit log. Fixed email templates prevent injection.
log-geofence-eventAuthenticated (base44.auth.me)Validates required fields, looks up the SafeZone server-side, verifies ownership, resolves viewer members from the SafeZone config, creates in-app notifications and emails for entry/exit events, and writes an audit log. Fixed email templates only.
notifyTaskAssignmentService roleCreates notifications when a task is assigned. Validates task_title. Returns the count of notifications created.
notifyMeetingScheduledService roleCreates notifications when a meeting is scheduled. Validates meeting_title. Returns the count of notifications created.
notifyCurriculumMilestoneService roleCreates a celebration notification when a child completes a parenting curriculum module. Validates child_name. Returns the created notification.
3 active workflows using the Base44 CNCF SWF format. Each is entity-triggered and invokes a backend function to deliver notifications. No scheduled (cron) workflows are currently registered.
Every entity has RLS rules configured in its schema. The standard pattern scopes records to the creating user (created_by_id: "{{user.id}}") for create, and allows read/update/delete by the owner or an admin. Sensitive entities (CareProfile, CareNote, CareCircleMember, Medication, ContinuityHandoverItem, ContinuityRelease) use read: null — making them readable by all authenticated family members so carers and family can coordinate, while writes remain owner-or-admin only.
Backend functions that handle location and identity (send-sos, log-geofence-event) derive the caller's identity from base44.auth.me() and resolve their Member record server-side. No request-supplied member ID or name is trusted. Email subjects and bodies use fixed templates with no user-controlled interpolation, preventing injection.
Notifications are classified into four tiers: routine, important, urgent, and emergency. Users can opt in/out per tier and per feature via NotificationPreference. Quiet hours can suppress non-emergency notifications, with an emergency override. Emergency SOS notifications bypass quiet hours.
Minor accounts have parental rules that can lock notification preferences. Kids Mode restricts the UI to age-appropriate features. Parental rules are marked is_lockedso children cannot override them.
All location sharing requires consent_acknowledged: true on the LocationShare record. Sharing modes (precise, approximate, journey-only) give granular control. Guardian-managed sharing is supported for minors. Location data is never shared without explicit user action.
Sensitive operations (SOS triggers, geofence events, subscription grants/revocations) are recorded in the AuditLog entity with event type, resource, action, result, user, and risk level. The Audit Log page is accessible to admins.
Checkout is public (no login gate) so storefront buyers can purchase. Prices are resolved server-side — the client sends only a product ID. Access is granted via the plan field written by the webhook (never is_verified, which is platform-protected). Webhook events are JWT-verified. Fulfillment is idempotent.
Famivanta is a paid-only platform — no free tier, no advertising, no selling family data. Four tiers serve four audiences: the single nuclear family, the connected extended family network of up to 3 nuclear families, the larger extended family network of up to 5 nuclear families, and organizations (businesses, churches, schools, NGOs, employers) that sponsor Famivanta access for their communities.
The customer pays for the product. The family's data is not the product. No advertising, no crippled free version, no per-member charges. One transparent family price gives access to the complete Family Operating System. Famivanta is not the cheapest family app — it is the platform where a family replaces several separate subscriptions and systems with one integrated operating layer.
One nuclear family. The complete Family Operating System.
Up to 3 connected nuclear families. For extended family networks, multi-generational coordination, and family governance.
Up to 5 connected nuclear families. For larger extended networks, multi-branch family governance, and cross-household coordination.
For businesses, churches, schools, NGOs, and employers. Bulk family licenses plus organization-level coordination tools.
Tell us about your organization and we'll prepare a custom proposal with volume pricing, module selection, and deployment timeline.
The matrix below shows exactly what each audience receives today (✓) and what arrives as the roadmap delivers (P0/P1/P2). Items marked with a priority code are planned future additions; see the Future Roadmap section for details.
| Feature / Capability | Family | Extended | Extended Plus | Enterprise |
|---|---|---|---|---|
| Core Platform | ||||
| Nuclear family household | ✓ | ✓ | ✓ | ✓ |
| Multi-household management | — | ✓ | ✓ | ✓ |
| Up to 3 connected nuclear families | — | ✓ | ✓ | ✓ |
| Up to 5 connected nuclear families | — | — | ✓ | ✓ |
| Extended family network directory | — | ✓ | ✓ | ✓ |
| Organization admin dashboard | — | — | — | ✓ |
| Group calendars & announcements | — | — | — | ✓ |
| Bulk family license distribution | — | — | — | ✓ |
| Anonymized wellbeing reporting | — | — | — | ✓ |
| Family Operations | ||||
| Calendar & events | ✓ | ✓ | ✓ | ✓ |
| Tasks, chores & approval workflow | ✓ | ✓ | ✓ | ✓ |
| Meals, recipes & shopping | ✓ | ✓ | ✓ | ✓ |
| Finance, budgets & transactions | ✓ | ✓ | ✓ | ✓ |
| Health records & appointments | ✓ | ✓ | ✓ | ✓ |
| Parenting curriculum & mentoring | ✓ | ✓ | ✓ | ✓ |
| Goals & habit tracking | ✓ | ✓ | ✓ | ✓ |
| Family meetings & governance | ✓ | ✓ | ✓ | ✓ |
| Legacy & Continuity | ||||
| Memories, photos & oral history | ✓ | ✓ | ✓ | ✓ |
| Legacy planning & timeline | ✓ | ✓ | ✓ | ✓ |
| Continuity plans & handover | ✓ | ✓ | ✓ | ✓ |
| Family tree & genealogy | ✓ | ✓ | ✓ | ✓ |
| Extended family genealogy (3+ branches) | — | ✓ | ✓ | ✓ |
| Extended family genealogy (5+ branches) | — | — | ✓ | ✓ |
| Family constitution & bylaws | ✓ | ✓ | ✓ | ✓ |
| Shared asset & property registers | — | ✓ | ✓ | ✓ |
| Safety & Care | ||||
| Consent-based family location | ✓ | ✓ | ✓ | ✓ |
| Safe zones & geofence alerts | ✓ | ✓ | ✓ | ✓ |
| SOS emergency alerts | ✓ | ✓ | ✓ | ✓ |
| Care profiles & care circle | ✓ | ✓ | ✓ | ✓ |
| Medication management | ✓ | ✓ | ✓ | ✓ |
| Care notes & journal | ✓ | ✓ | ✓ | ✓ |
| AI & Intelligence | ||||
| AI Assistant (deterministic insights) | ✓ | ✓ | ✓ | ✓ |
| Universal Family Inbox | P0 | P0 | P0 | P0 |
| AI Capture (screenshots, voice, PDF) | P0 | P0 | P0 | P0 |
| Evidence-grounded AI Historian | P1 | P1 | P1 | P1 |
| Family Automation Engine | P1 | P1 | P1 | P1 |
| Open Banking integration | P2 | P2 | P2 | P2 |
| Platform & Integrations | ||||
| Offline-first architecture | ✓ | ✓ | ✓ | ✓ |
| Calendar sync (Google/Outlook/Apple) | P1 | P1 | P1 | P1 |
| GEDCOM 7 import/export | P0 | P0 | P0 | P0 |
| Integration Hub | P1 | P1 | P1 | P1 |
| Famivanta Developer API | P2 | P2 | P2 | P2 |
| FHIR health-data compatibility | P2 | P2 | P2 | P2 |
| Custom integrations & API access | — | — | — | ✓ |
| Dedicated account manager | — | — | — | ✓ |
| SLA & priority support | — | ✓ | ✓ | ✓ |
✓ = included now · P0 = near-term · P1 = mid-term · P2 = long-term · — = not included
Famivanta is not an "all-in-one family app." It is the intelligent operating layer connecting the people, responsibilities, information, history, and future of a family. The roadmap below represents 12 prioritized additions plus the Integration Hub and Developer Platform — each chosen because it differentiates Famivanta from the products we analysed (Famora, Kinora, KinWeave, KinVault, KinOrbit, KinHarbor, Kinsora). The moat is not the number of features; it is the connection between them.
Core: Famivanta Family Graph — every core object (Person, Relationships, Households, Roles, Calendar, Tasks, Money, School, Health, Care, Documents, Location, Memories, Assets, Goals, Decisions, Legacy) connects to it.
Intelligence: Famivanta Intelligence Layer — capture, extraction, search, recommendations, conflict detection, automations, summaries, and planning across all modules.
Experience: Famivanta Experience Layer — parent, child, teenager, spouse, elder, extended family, and professional experiences, each surfacing the right information for that role.
Trust: Famivanta Trust Layer — identity, consent, permissions, encryption, audit, offline-first, recovery, and succession — surrounding everything.
A single intake point where families forward or upload school emails, PDFs, screenshots, letters, invoices, receipts, travel bookings, voice recordings, photographs, and medical appointment letters. Famivanta AI asks 'What should I do with this?' and proposes actions: add event, create task, add expense, store document, add shopping item, update member, add memory, add health appointment, or create reminder.
A parent uploads a school newsletter and Famivanta identifies sports day, parents' evening, school closure, £15 trip fee, permission-slip deadline, required packed lunch, and uniform requirement. Instead of one calendar entry, it proposes calendar events, tasks, finance items, shopping items, reminders, and document storage — all from a single source.
Full support for GEDCOM 7 (the current official specification with GEDZip media packaging), while remaining compatible with GEDCOM 5.5 and 5.5.1 files. Import from CSV, structured JSON, and spreadsheets. A family with 2,000 existing ancestors should not have to recreate its tree manually.
When importing large family trees, Famivanta analyses for possible duplicates, conflicting dates, incomplete relationships, and unsupported fields — then guides the user through resolution before committing the import. For sync conflicts (two people editing the same event offline), it shows both versions and offers merge.
A user can ask: 'Who was the first person in our family recorded as living in London?' or 'Which family members moved from Nigeria to Britain?' The AI answers with citations: passport scan, interview transcript, tenancy document — and a confidence level (High / Uncertain). It can also generate interview questions for living relatives.
Rule-based automations that connect modules: 'When a school event is imported → add child, add relevant parent, check calendar conflicts, check transport, remind 48 hours before.' 'When a passport has fewer than six months remaining → notify owner, notify designated parent, create renewal task.' 'When Grandpa has a medical appointment → notify Care Circle, create transport task, display medication list.'
Location modes: Off, Temporary (15m / 1h / journey / school trip / day), Routine (trigger-based: 'Notify Dad when Cedric reaches football practice'), Emergency (SOS), Care (consenting elder shares with designated carers), and Travel. Intelligent geofencing that understands operational consequences: 'Chris reached school → mark arrival confirmed, stop travel-sharing, notify parent, complete school drop-off task, remove transport warning.'
Dedicated elder-care experience: care circle (who helps — daughter, son, neighbour, nurse, doctor, paid carer, church member, emergency contact), care calendar (appointments, carers, medication, meals, transport, visits), medication support (name, schedule, adherence, refill, pharmacy, prescribing clinician), care journal (wellbeing observations, changes, questions), care documents (care plan, power of attorney, allergies, insurance), and respite coordination ('Mum has provided 27 hours of care this week — another family member may need to cover Saturday').
While alive, a person records: financial (banks, insurance, pensions, investments, debts, subscriptions), property (deeds, mortgages, rental, land, keys), digital (accounts, domain names, digital assets), legal (will location, solicitor, executor, power of attorney), practical (utilities, vehicles, household instructions, pet arrangements), and personal (messages, wishes, funeral preferences, family history). The killer feature: conditional handover — 'On verified incapacity, release my Emergency Financial Folder to Chimzi' or 'On verified death, release my Family Handover Plan to my nominated executor.'
A central hub under Settings → Integrations showing all connected services: Calendars (Google, Microsoft, Apple, ICS), Genealogy (GEDCOM, FamilySearch API, future partners), Finance (Open Banking via regulated providers like TrueLayer, banks, payment providers), Communications (email, SMS, WhatsApp, push), Schools (ICS, email ingestion, future school-information-system connectors), Health (FHIR-compatible services), Maps (location/mapping provider), and Storage (approved cloud export destinations).
Connect Famivanta Money to UK Open Banking via a regulated provider (e.g. TrueLayer) for account data, balances, transactions, cards, standing orders, and direct debits. Display household spending, school expenses, grocery trends, subscriptions, and family savings progress — all with explicit user consent and never storing bank credentials.
Make the family health module compatible with FHIR (the HL7 standard for health-data exchange) so that, in the future, authorised healthcare integrations can exchange Patient, Practitioner, CareTeam, and related resources — without Famivanta inventing a proprietary healthcare interchange format.
An external API with OAuth 2, granular scopes (calendar.read, calendar.write, school.events.write, tasks.read, tasks.write, family.basic.read, genealogy.read, genealogy.write, documents.selected.read, finance.summary.read, care.schedule.read, emergency.profile.read), revocable consent, audit history, rate limits, webhooks, token rotation, and tenant isolation. A school integration never receives marriage information, finances, health history, or private memories — only what its scoped token permits.
Famivanta becomes an orchestration layer — it does not rebuild external services, it connects them through a single trusted hub with consistent consent, audit, and privacy controls.
An external API with OAuth 2, granular scopes, revocable consent, audit history, rate limits, webhooks, token rotation, and tenant isolation. A school integration receives only what its scoped token permits — never marriage information, finances, health history, the family vault, or private memories.
calendar.readcalendar.writeschool.events.writetasks.readtasks.writefamily.basic.readgenealogy.readgenealogy.writedocuments.selected.readfinance.summary.readcare.schedule.reademergency.profile.readNever family.all for a third-party application. Every scope is narrow, revocable, and audited.
Grandmother dies. An ordinary app sees separate pieces: the calendar app deletes appointments; the genealogy app marks her deceased; the vault stores a death certificate; the finance app does nothing; the location app stops sharing. Famivanta understands this as one family life event and asks authorised people: cancel upcoming appointments? End care schedules? Preserve the profile as a memorial? Record date and place of death? Upload the death certificate? Notify nominated family members? Activate the Continuity Plan? Review responsibilities previously owned by this person? Preserve photographs and stories? Update the family tree? Prepare a funeral coordination workspace? Review family assets requiring attention? That is a Family Operating System.