Review 5 of 6: UX, interruption management, explainability

Reviewer lens: what Byron actually sees and feels on his phone. Inputs: docs/PRD-original.md and docs/DESIGN-DRAFT.md (2026-10-03).

Android behaviors that I have not verified on a device are marked [verify] and collected in §S. Do not take them as fact.

TL;DR

  1. Annotate mode stays the default, with one change: no annotation for Recognized senders. Annotate only messages from senders who aren't Recognized. The sidecar's note must vanish when the original is read or dismissed. Show a tiny persistent "sidecar active" indicator so "no note" never gets confused with "sidecar dead".
  2. Rename "Quiet unknowns" to "Re-ring" mode and ship it only with three failsafes.
  1. Lead the verdict card with a chip plus one plain sentence. The five dimensions go into a four-cell strip (Who / Context / Risk signals / Visibility). Raw numbers sit behind a "Scores" expander. Unknown senders get a grey chip, never amber, and no verdict ever uses the word "spam".
  2. "Ask who this is" is the primary action for Unrecognized messages only. Hide it for Likely scam, for tripwires, for short codes and alphanumeric senders, for group threads, and for Cannot assess. Next to it, offer "Wait for them" (a reminder in 2 h). Most real people follow up anyway.
  3. Be honest about the value case. Detection will be worse than Google's, and Google-filtered spam is invisible to the sidecar anyway. The sidecar is worth it for five things:

Kill criterion: see §7.


§1. Re-notify modes: Annotate vs Quiet unknowns

1.1 Failure modes in the draft

#FailureModeSeverityCause
F1Double notifications. Each message produces two shade entries (Messages plus sidecar), and both persist after one is read.BothHigh (daily annoyance)No lifecycle link between the original and the companion notification.
F2Silent messages when the sidecar is dead.Re-ringCriticalThe Messages channel is set to silent, and nothing re-alerts. Samsung kills the process, an update unbinds the listener, or Samsung's "Auto optimize daily" restart drops it.
F3The buzz arrives before the verdict.AnnotateMediumMessages alerts at post time. The sidecar can only annotate afterwards, so Annotate never reduces interruption. It only adds information. Be explicit that Annotate does not meet the PRD goal "low-confidence unknowns less interruptive".
F4Latency on re-ring. A known contact rings late, or rings twice.Re-ringMediumThe LLM or a slow DB read sits in the alert path. If the original channel was also audible (a priority conversation), the phone rings twice.
F5Alert throttling. Bursts of re-rings get quieter or are dropped.Re-ringLow to mediumAndroid rate-limits notification posts per app. Android 15 "notification cooldown" lowers volume for rapid successive alerts from one app [verify on Samsung One UI; it may be Pixel-only]. Because every message re-rings through one app (the sidecar), cooldown hits the sidecar harder than it hit Messages.
F6Thread updates re-classified.BothMediumGoogle Messages updates the same notification key as the thread grows (the MessagingStyle tail). Without dedupe on per-message timestamps, the same message gets re-annotated and re-rung.
F7Snoozed scam notification lost.Re-ringMediumThe snooze is unbounded, or the Messages re-post behaviour while snoozed is unknown [verify].
F8Sidecar notification leaks text on the lock screen.BothMediumThe companion duplicates message spans. Lock-screen redaction of the original doesn't carry over to ours.

1.2 What Android and Google Messages actually let the user configure

1.3 Recommended design

Mode A: Annotate (default, zero risk to reachability)

Mode B: Re-ring (opt-in, labelled "Quiet unknowns (re-ring)")

Setup is guided, with screenshots, and the sidecar checks every step itself:

  1. Mark the top 5 to 15 people as Priority conversations in Android. These ring through Android directly. This is the failsafe that keeps the most important people reachable even when the sidecar is dead. It depends on spike item S1: a Priority conversation must still alert when the parent channel is Silent. If S1 fails, Re-ring is not shippable on that device, and the setup flow must say so.
  2. Set the Google Messages incoming channel to Silent. Not Off: messages stay in the shade and on the lock screen, they just don't make a sound.
  3. Sidecar routing. It posts on its own per-verdict channels, so Byron tunes alerting with Android's native UI instead of an in-app settings screen.
Sidecar channelDefault importanceUsed for
ring_knownHIGH, soundRecognized and Likely legitimate. Skipped if getLastAudiblyAlertedMillis shows the original already rang (Priority conversation).
quiet_unknownLOW, silentUnrecognized. Optionally batched as an hourly "3 unknown messages since 2 pm" summary.
cautionDEFAULT, no sound, visibleSuspicious.
scam_patternMIN, silentLikely scam. The original is snoozed for a finite 8 h, never cancelled.
cannot_assessHIGH, soundCannot assess. When in doubt, ring. A redacted OTP is often something he's waiting for.
healthHIGH, sound, bypass DND if grantedWatchdog alarm (below).
  1. Ring fast (fixes F4). Re-ring decisions come from the deterministic engine only, with a budget under 300 ms from onNotificationPosted. The LLM, if enabled, can update the card afterwards but never gates the ring.
  2. Ring the companion, keep the original (fixes F1 in Re-ring). Post the companion as heads-up with setTimeoutAfter(~10 s). It rings, shows the verdict chip, then disappears and leaves the original Messages notification (with its inline reply) as the one shade entry. The verdict stays one tap away in the sidecar app.

Failsafes for F2 (sidecar dead means silent messages):

FailsafeMechanismCovers
Priority conversationsAndroid rings top contacts natively, independent of the sidecar.The most important people are reachable even if everything else fails.
Listener rebindonListenerDisconnected → requestRebind(component); BOOT_COMPLETED / MY_PACKAGE_REPLACED receivers → rebind.Updates, reboots, the Samsung daily restart.
WatchdogWorkManager periodic job (15 min minimum) plus an exact alarm. It checks that the listener is connected and that the last heartbeat is recent. If disconnected for more than 2 min: a loud health notification, "Message check is off. Messages are SILENT. Tap to fix / switch to normal alerts."Process killed while the app can still schedule work.
Missed-message sweepOn reconnect, getActiveNotifications() and re-classify anything from Messages posted while we were down. Any found → ring once with "N messages arrived while message check was off".Catch-up after a gap.
Deadman by designEach snooze is finite (8 h), so the system restores the notification even if we never come back.Scam snoozes.
One-tap revertThe setup screen and the health alert both deep-link to the Messages channel settings to un-silence it. The sidecar can't do it for him.Recovery.
Honest copyThe Re-ring toggle says: "If this app stops, only your Priority conversations will make a sound."Informed consent.

The residual risk the watchdog can't cover is a force-stopped app: Samsung "deep sleeping", or a user force-stop, which kills alarms too. That's why the Samsung "Never sleeping apps" step in §4 is mandatory for Re-ring and checked at runtime. If the app is not on that list, Re-ring refuses to turn on.

Lock screen (fixes F8): every sidecar notification uses VISIBILITY_PRIVATE with a text-free publicVersion, for example "Message check: Unknown sender". Quoted spans never reach the lock screen.


§2. Verdict card: presenting five dimensions without overwhelming

2.1 Principles

2.2 The six verdicts: chip, colour, one-line "why" template

Verdict (internal)Chip textColourOne-line why (template)Never say
RecognizedKNOWNblue-grey"In your contacts as {name}." / "You trusted this number on {date}."
Likely legitimateLIKELY OKgreen"Says it's {org}; matches your note '{ledger entry}'." / "Short code {code} is {brand}'s known number.""Safe", "verified"
Unrecognized / insufficient contextUNKNOWNneutral grey"Not in contacts. {No name given / No link / No request}. Not enough to judge either way.""Spam", "suspicious", "unverified sender" (reads as an accusation)
SuspiciousCAUTIONamber"Asks you to {pay / move to WhatsApp / share a code}: a common scam step. Could still be real.""Spam", "fraud"
Likely scam / phishingSCAM PATTERNred"Link goes to {domain}, not {brand}. Matches the fake-{toll/delivery} pattern.""Spam", "definitely", "fraudster"
Cannot assessCAN'T SEEgrey, dashed outline"Preview was {hidden / redacted by Android / cut off}. Open in Messages to read it."Any risk language

The golden case, "Are you working today?", renders as:

UNKNOWN · "Not in contacts. No name, no link, no request. Real people and wrong-number scams both open like this, so I'll watch the next message."

2.3 "What would change this verdict" (deterministic counterfactuals)

FromLines shown (max 3)
UNKNOWN"+ They say who they are and it matches something you're expecting → LIKELY OK" · "+ You mark them trusted → KNOWN" · "- Next message has a link, asks for money or a code, or moves to another app → CAUTION"
LIKELY OK"- A link to a domain that isn't {brand} → SCAM PATTERN (your expected-sender note can't override this)"
CAUTION"+ Nothing in their texts can clear this. Check through {brand}'s official app or number." · "- A payment or code request → SCAM PATTERN"
SCAM PATTERN"Nothing they send can change this. If you think it's real, contact {brand} directly, not via this message."
CAN'T SEE"+ Turn on full previews (Settings > ...) → I can read it next time."
KNOWN + risk codes"Possible compromised account: confirm with {name} by calling, not by replying."

2.4 Scores expander

For Byron, who is technical, keep the numbers one tap away:

Scores                         (log-odds view: on)
  identity       12  ##........   UNKNOWN_SENDER (-0.1)
  context         0  ..........   -
  scam_risk      18  ##........   GENERIC_OPENER (+0.4), prior 0.08
  legitimacy     10  #.........   derived: identity + context - risk
  completeness  100  ##########   full text, sender id present
  rule fired:  #6 "otherwise -> Unrecognized"
  engine: deterministic v0.3 · LLM: off · network: none

§3. "Ask who this is"

3.1 Draft options (user picks a default; always editable in Google Messages)

  1. Neutral (default): "Hi, sorry, I don't have this number saved. Who is this?"
  2. Warmer: "Hi! This number isn't in my phone. Who am I talking to?"
  3. Business-aware (offered when the text claims an org): "Hi, which company is this from? I'll follow up through your official number."
  4. New-number friend (when the text claims a relationship, such as "it's me, new phone"): "Hey, new number? Remind me who this is, and send a quick hello from your old number or email so I know it's you."

Rules every draft follows:

3.2 When to offer it

SituationAsk-who offered?Why
UNKNOWN, 1:1, long-code numberPrimary actionThis is the case it exists for.
LIKELY OK but the identity isn't confirmedSecondaryCheap confirmation.
CAUTION without a tripwire (for example a generic opener plus a relationship claim)Secondary, with the note "Replying tells the sender this number is active."Real risk, low cost. Let him choose.
CAUTION with a tripwire, or SCAM PATTERNHidden. Show "Block & report in Messages" instead.Replying confirms a live number and invites the follow-up script.
Short code or alphanumeric sender IDHiddenThese can't receive a conversational reply. A reply may be read as a keyword.
Group threadHiddenThe question would go to everyone.
CAN'T SEEHiddenHe hasn't seen the content. It might be an OTP he's waiting for.
KNOWNHiddenNot needed.
Email-gateway or iMessage-relay style sendersHiddenReplies go somewhere unexpected.

Always offer "Wait for them" next to it. It's a sidecar-local reminder: "Remind me in 2 h if they don't say more". Legitimate senders usually follow up with context (a name or a reason) within minutes. The reminder needs no reply, so it confirms nothing.

3.3 The hidden win: read without a read receipt

Opening the thread in Google Messages sends an RCS read receipt (if read receipts are on). That tells a scammer the number is live and someone read the message.

The sidecar card shows the full preview the listener already received, without opening Messages, and the sidecar never fires the "Mark as read" action. Say this on the card for UNKNOWN, CAUTION and SCAM PATTERN: "Read here: the sender won't get a read receipt." [verify: read receipts and typing indicators fire only on open in Messages, not on notification delivery]


§4. Onboarding

Target: under 4 minutes, with every step self-verified by the app. No "did you do it?" checkboxes.

StepWhat Byron doesWhat the app verifiesNotes
0. InstallPrefer adb install from the Mac over a downloaded APK.n/aADB installs may be exempt from restricted settings and from region-gated Play Protect sideload blocking [verify both]. Google's developer-verification rollout for sideloaded apps (2026 onward, region-phased) may eventually require a registered developer identity even for personal APKs [verify current status for the US; ADB/dev installs were described as exempt]. Play Protect may still scan and warn.
1. Restricted settings (Android 13+, only for browser- or file-manager-installed APKs)Try to enable Notification Access → "Restricted setting" dialog → App info → ⋮ → Allow restricted settings → authenticate → come back.Whether NotificationManagerCompat.getEnabledListenerPackages() contains us.Show the exact screens. The ⋮ menu option only appears after the first blocked attempt, which is the confusing part.
2. Notification AccessDeep link Settings.ACTION_NOTIFICATION_LISTENER_DETAIL_SETTINGS with our component (API 30+). Toggle on.The listener connects (onListenerConnected).Copy: "Reads notifications from Google Messages only. Never sends, deletes or opens anything. This app has no internet permission." Link to the manifest proof in-app.
3. Samsung batterySettings > Battery > Background usage limits > Never sleeping apps > add. Also App info > Battery > Unrestricted. Then App info > "Pause app activity if unused" → off.PowerManager.isIgnoringBatteryOptimizations(). The Samsung list membership can't be read via API, so ask once and then infer from heartbeat gaps.Mandatory for Re-ring, recommended for Annotate. Mention Samsung "Auto optimize daily" restarts and that we rebind after them.
4. Live test"Text this phone from any other phone: Are you working today?"The listener sees a Messages notification. The card shows a field-coverage report: sender id ✓, full text ✓, Person uri tel: ✓, actions ✓, redacted ✗.This doubles as the §6.2 feasibility probe UI. The verdict must be UNKNOWN. That's the golden case, live.
5. Mode choiceAnnotate (default) or Re-ring (runs the §1.3 guided setup, including Priority conversations).For Re-ring: S1 behaviour observed live. A Priority contact texts while the sidecar is force-stopped and the phone still rings.Only offered after step 3 passes.
6. OptionalAdd 1 to 3 expected senders now (§4.1). Optionally grant READ_CALENDAR.n/aSkippable. Remind after 3 days.

4.1 Expected-senders ledger entry: make it 5 seconds

The ledger is the product's main differentiator (draft §B), and it dies if adding an entry feels like a form. Entry points, fastest first:

  1. From a card, after the fact: "I was expecting this". One tap adds the sender and entity to the ledger and trusts the thread. This is the highest-volume path.
  2. Share sheet: share a booking-confirmation email, calendar invite or screenshot text into the sidecar. A local deterministic parser (brand dictionary plus date words) proposes "FedEx · until Fri" and he confirms with one tap. No network.
  3. Quick Settings tile and launcher long-press shortcut "Expecting…" These open a one-line field with type chips: Delivery Appointment Service visit New job/colleague Travel Person.
  4. Voice: use the keyboard mic (Gboard / Samsung voice typing) in that one-line field. Don't add our own speech recognizer: it adds no permission, and our app keeps no INTERNET. Be honest that the keyboard's recogniser may use the network, depending on Gboard's offline setting.

Parsing examples. The default expiry is 7 days for deliveries, the event date plus 1 day for appointments, and 30 days for people.

"fedex this week"            -> Delivery · FedEx · expires Sun
"dentist thu bright smile"   -> Appointment · Bright Smile Dental · Thu (+1d)
"carlos building ashford"    -> Person · Carlos · The Ashford · 30d

Ledger entries render as chips on the main screen with a countdown. Swipe to delete. An expired entry fades for a day before it's removed.


§5. Feedback UX (low effort)


§6. Review screen and sender history

The main screen has three zones: "Needs a look", "Expecting", and "Recent". The sender page shows the trajectory as a vertical timeline, so the multi-message pivot (draft §A, the stateful differentiator) is visible:

 +555 0142  (unnamed)                           [ UNKNOWN -> CAUTION ]
 ---------------------------------------------------------------------
  Tue 09:12  UNKNOWN   "Are you working today?"
             GENERIC_OPENER
  Tue 09:40  UNKNOWN   "Sorry wrong number! I'm Amy, nice to meet you"
             WRONG_NUMBER_PIVOT  (+ trajectory: opener -> pivot)
  Tue 10:05  CAUTION   "...chat on [WhatsApp]?"
             PLATFORM_SHIFT      (+ trajectory: 3-step pattern)
 ---------------------------------------------------------------------
  Pattern: opener -> wrong-number pivot -> platform shift
  This sequence is typical of investment/romance scams. Any one
  message alone was not enough.
 ---------------------------------------------------------------------
  [ Block & report in Messages ]  [ I know them ]  [ Forget sender ]

§7. Why install this over Google Messages' built-in protection (honest)

What Google Messages already does better:

What the sidecar does that Google Messages doesn't:

  1. Explains. Google says "suspected spam". The sidecar says which words, which domain, which rule, and what would change its mind.
  2. The expected-senders ledger. It knows he's expecting FedEx or that Carlos manages his building. Google can't.
  3. Treats unknown as unknown, not bad. It quiets unknowns without calling them spam (Re-ring mode), and native Android can't silence "new unknown conversations" at all.
  4. Reads without a read receipt. He can triage UNKNOWN and CAUTION without telling the sender the number is live.
  5. Trusts senders without polluting Contacts, and keeps an inspectable per-sender history with the trajectory view.
  6. Auditable privacy. No INTERNET permission, enforced by the manifest.

Kill criterion (propose to the consolidator): run the Phase 0 probe in shadow for 14 days. If it sees fewer than ~5 unknown-sender, non-short-code messages per week, or Google's own filtering already handles nearly all the scams he gets, the value is too thin. In that case ship only the probe plus the expected-senders card, or stop. Byron should set the actual threshold.


§W. Wireframes (ASCII)

W1. Notifications: Annotate mode, Unknown (expanded) under the original

+---------------------------------------------------------------+
| Messages · now                                                |
| (555) 010-0142                                                |
| Are you working today?                                        |
|  [Reply]  [Mark as read]                                      |
+---------------------------------------------------------------+
| Message check · now                                (silent)   |
| [ UNKNOWN ]  (555) 010-0142                                   |
| Not in contacts. No name, no link, no request.                |
| Not enough to judge either way.                               |
|  [Ask who this is]   [I know them]   [Wait 2h]                |
+---------------------------------------------------------------+
 lock screen public version:  "Message check: Unknown sender"

W1b. Re-ring heads-up, Likely legitimate (auto-dismisses after ~10 s)

+---------------------------------------------------------------+
| Message check · now                              (rings)      |
| [ LIKELY OK ]  72789 · "FedEx: your package arrives today..." |
| Short code matches FedEx; you're expecting FedEx (till Sun).  |
+---------------------------------------------------------------+

W1c. Scam pattern (original snoozed 8 h; this card is MIN/silent)

+---------------------------------------------------------------+
| Message check                                                 |
| [ SCAM PATTERN ]  +1 (888) 555-0199                           |
| Link goes to ezdrive-pay.top, not a government domain.        |
|  [See why]   [Block & report in Messages]   [This is real]    |
+---------------------------------------------------------------+

W2. Verdict card (bottom sheet opened by tapping the notification)

+---------------------------------------------------------------+
|  ____                                                         |
| [ CAUTION ]                       +1 (555) 010-0177  · 10:05  |
|                                                               |
| Asks you to continue on WhatsApp: a common scam step.         |
| Could still be real.                                          |
|                                                               |
|  Who        Context      Risk signals     Visibility          |
|  Unknown    None         2 found          Full text           |
|                                                               |
| "Hi it's Amy again :) can we chat on [WhatsApp]? My number    |
|  is [+44 7700 900123]"                                        |
|   ^ highlighted spans = evidence                              |
|                                                               |
| Read here: the sender won't get a read receipt.               |
|                                                               |
| v Why (3)                                                     |
|   ! PLATFORM_SHIFT     "chat on WhatsApp"         raises risk |
|   ! WRONG_NUMBER_PIVOT  earlier: "Sorry wrong number!"  risk  |
|   . UNKNOWN_SENDER     not in contacts        (weak, capped)  |
|                                                               |
| v What would change this                                      |
|   - A payment or code request -> SCAM PATTERN                 |
|   + Nothing in their texts can clear this; verify another way |
|                                                               |
| > Scores (numbers, rule fired, engine version)                |
|                                                               |
| [ Open in Messages ]  [ Block & report in Messages ]          |
| [ This is real ]      [ Sender history ]                      |
+---------------------------------------------------------------+

W3. Main screen

+---------------------------------------------------------------+
| Message check            ( * ) on · last seen Messages 2m ago |
+---------------------------------------------------------------+
| EXPECTING                                         [+ Expecting]|
|  ( Delivery · FedEx · 3d )  ( Appt · Bright Smile · Thu )     |
|  ( Person · Carlos/Ashford · 27d )                            |
+---------------------------------------------------------------+
| NEEDS A LOOK (3)                                              |
|  [ UNKNOWN ]  (555) 010-0142   "Are you working today?"  9:12 |
|  [ CAUTION ]  (555) 010-0177   "chat on WhatsApp?"      10:05 |
|  [ CAN'T SEE ] 72000            preview hidden by Android 10:30|
+---------------------------------------------------------------+
| RECENT                                         filter: all  v |
|  [ SCAM PATTERN ] (888) 555-0199  toll link (snoozed 8h)  8:01 |
|  [ LIKELY OK ]    72789 FedEx     matches Expecting        7:40|
|  (KNOWN messages are not listed unless "show known" is on)    |
+---------------------------------------------------------------+
| [ Review week (6) ]                  [ Settings / Privacy ]   |
+---------------------------------------------------------------+

Changes I'd make to DESIGN-DRAFT

Draft §Change
EAnnotate: no companion for Recognized; lifecycle-link companions to the original (onNotificationRemoved cancels them); update in place with setOnlyAlertOnce.
ERename "Quiet unknowns" to "Re-ring". Require Priority conversations for top contacts (gated on S1), plus the watchdog, the missed-message sweep and a verified Never-sleeping-apps entry. Per-verdict sidecar channels. Cannot assess rings.
ERe-ring the companion via heads-up with setTimeoutAfter. Dedupe against Ranking.getLastAudiblyAlertedMillis() (API 29+). Deterministic-only alert path under 300 ms.
ESnooze is finite (8 h) and never cancelNotification.
DAdd "Wait for them" (reminder) next to "Ask who this is". Add the §3.2 hide rules. Add the "Read here, no read receipt" affordance. Drafts must not answer embedded questions or say "wrong number".
DFeedback: per-verdict targeted actions (§5) instead of a generic "this was wrong". Always show the effect of the correction.
BLedger entry via card ("I was expecting this"), share sheet, QS tile and keyboard voice. Default expiries per type.
AVerdict copy table (§2.2). Unknown = grey chip. Counterfactuals generated from the decision table. legitimacy_confidence hidden outside the Scores expander.
G / newAll sidecar notifications VISIBILITY_PRIVATE with a text-free public version.
HProbe APK step 4 doubles as the onboarding field-coverage report. Add the §S items to the probe's test script.

§S. Spike items from this review (feed into PRD §6.2)

#Claim to verifyWhy it's load-bearingHow to test on the Samsung (and Pixel if available)
S1A conversation marked Priority in Android still alerts audibly when the parent Google Messages channel is Silent.Re-ring's only failsafe for top contacts when the sidecar is dead. If this fails, Re-ring is not shippable.Set the parent channel to Silent and one thread to Priority. Force-stop the sidecar. Text from that contact and confirm sound or vibration. Repeat after a reboot.
S2Ranking.getLastAudiblyAlertedMillis() is populated correctly for Messages notifications on One UI.Prevents double ringing.Probe logs the value for silent-channel and priority-thread messages.
S3Behaviour of a snoozed Messages notification when the same key is re-posted (the next message in the thread), and across a reboot.The scam-snooze design, and avoiding lost messages.Snooze via the probe, send a second message, observe. Reboot mid-snooze.
S4Google Messages on his build/region has (or lacks) a native unknown-sender filter.It might make Re-ring partly redundant.Inspect Messages settings: Spam protection and any filter options.
S5Google Scam Detection is available on his Samsung model and region.§7 overlap and honesty.Check Messages > Settings > Protection & Safety.
S6adb install is exempt from the restricted-settings gate.Onboarding friction.Install via adb and via a browser download. Compare the Notification Access flow.
S7Developer-verification and Play Protect sideload blocking status for notification-listener apps in the US as of the build date.Whether the APK installs at all in future.Check Google's current Android developer verification docs at build time. Attempt a non-ADB install.
S8An RCS read receipt fires only on opening the thread in Messages, not on notification delivery or listener access.The "read without receipt" claim on the card.Use a second RCS phone with receipts on. Read via the sidecar card only, then check the sender's view.
S9Android 15+ notification cooldown exists on One UI and affects a third-party app's rapid alerts.Re-ring bursts get quieter.Send 5 messages in 20 s with Re-ring on and listen.
S10Listener rebind succeeds after the Samsung "Auto optimize daily" restart and after an app update.Silent-sidecar risk.Trigger both, then check onListenerConnected timing in the probe log.
S11setTimeoutAfter heads-up behaviour on One UI: it rings, shows briefly, then disappears cleanly.The single-shade-entry design for Re-ring.Probe posts a test notification.
S12The per-conversation channel and Ranking.getConversationShortcutInfo() are exposed for Messages threads.Mapping a notification to a conversation without private APIs.Probe logs the channel id and shortcut id per thread.

← Back to the proposal