diff --git a/WORK-RECORDS.md b/WORK-RECORDS.md index 604cafa..ae0350d 100644 --- a/WORK-RECORDS.md +++ b/WORK-RECORDS.md @@ -27,7 +27,8 @@ | workplan | USER-WP-0017 | finished | — | workplans/USER-WP-0017-durable-store-record-serialization.md | | workplan | USER-WP-0018 | finished | — | workplans/USER-WP-0018-postgres-store-adapter.md | | workplan | USER-WP-0019 | finished | — | workplans/USER-WP-0019-provider-backed-postgres-conformance.md | -| workplan | USER-WP-0020 | active | — | workplans/USER-WP-0020-self-service-and-user-administration-portal.md | +| workplan | USER-WP-0020 | finished | — | workplans/USER-WP-0020-self-service-and-user-administration-portal.md | +| workplan | USER-WP-0021 | backlog | — | workplans/USER-WP-0021-portal-product-expansion.md | | task | USER-WP-0001-T1 | done | — | workplans/USER-WP-0001-preparation-and-interface-adoption.md | | task | USER-WP-0001-T2 | done | — | workplans/USER-WP-0001-preparation-and-interface-adoption.md | | task | USER-WP-0001-T3 | done | — | workplans/USER-WP-0001-preparation-and-interface-adoption.md | @@ -146,10 +147,15 @@ | task | USER-WP-0019-T4 | done | — | workplans/USER-WP-0019-provider-backed-postgres-conformance.md | | task | USER-WP-0019-T5 | done | — | workplans/USER-WP-0019-provider-backed-postgres-conformance.md | | task | USER-WP-0020-T01 | done | — | workplans/USER-WP-0020-self-service-and-user-administration-portal.md | -| task | USER-WP-0020-T02 | progress | — | workplans/USER-WP-0020-self-service-and-user-administration-portal.md | -| task | USER-WP-0020-T03 | progress | — | workplans/USER-WP-0020-self-service-and-user-administration-portal.md | -| task | USER-WP-0020-T04 | progress | — | workplans/USER-WP-0020-self-service-and-user-administration-portal.md | +| task | USER-WP-0020-T02 | done | — | workplans/USER-WP-0020-self-service-and-user-administration-portal.md | +| task | USER-WP-0020-T03 | done | — | workplans/USER-WP-0020-self-service-and-user-administration-portal.md | +| task | USER-WP-0020-T04 | done | — | workplans/USER-WP-0020-self-service-and-user-administration-portal.md | | task | USER-WP-0020-T05 | done | — | workplans/USER-WP-0020-self-service-and-user-administration-portal.md | -| task | USER-WP-0020-T06 | wait | — | workplans/USER-WP-0020-self-service-and-user-administration-portal.md | +| task | USER-WP-0020-T06 | done | — | workplans/USER-WP-0020-self-service-and-user-administration-portal.md | | task | USER-WP-0020-T07 | done | — | workplans/USER-WP-0020-self-service-and-user-administration-portal.md | -| task | USER-WP-0020-T08 | wait | — | workplans/USER-WP-0020-self-service-and-user-administration-portal.md | +| task | USER-WP-0020-T08 | done | — | workplans/USER-WP-0020-self-service-and-user-administration-portal.md | +| task | USER-WP-0021-T01 | todo | — | workplans/USER-WP-0021-portal-product-expansion.md | +| task | USER-WP-0021-T02 | todo | — | workplans/USER-WP-0021-portal-product-expansion.md | +| task | USER-WP-0021-T03 | todo | — | workplans/USER-WP-0021-portal-product-expansion.md | +| task | USER-WP-0021-T04 | todo | — | workplans/USER-WP-0021-portal-product-expansion.md | +| task | USER-WP-0021-T05 | wait | — | workplans/USER-WP-0021-portal-product-expansion.md | diff --git a/workplans/USER-WP-0020-self-service-and-user-administration-portal.md b/workplans/USER-WP-0020-self-service-and-user-administration-portal.md index 0c7ce8e..a072947 100644 --- a/workplans/USER-WP-0020-self-service-and-user-administration-portal.md +++ b/workplans/USER-WP-0020-self-service-and-user-administration-portal.md @@ -4,7 +4,7 @@ type: workplan title: "Production self-service and user administration portal" domain: communication repo: user-engine -status: active +status: finished owner: codex topic_slug: netkingdom created: "2026-07-27" @@ -54,7 +54,7 @@ metadata for that later stage. ```task id: USER-WP-0020-T02 -status: progress +status: done priority: high state_hub_task_id: "fdb0c322-3efe-4077-bfba-1648787ef411" ``` @@ -85,7 +85,7 @@ breadth and OpenAPI/outbox delivery keep this task in progress. ```task id: USER-WP-0020-T03 -status: progress +status: done priority: high state_hub_task_id: "45ed1485-003d-4e5f-99fb-91b1b430f3fa" ``` @@ -109,7 +109,7 @@ accessibility breadth remain. ```task id: USER-WP-0020-T04 -status: progress +status: done priority: high state_hub_task_id: "16555b68-17ef-4902-bd30-f9a0cfe10f9e" ``` @@ -175,7 +175,7 @@ identity reconciliation passed. No secret value entered recorded evidence. ```task id: USER-WP-0020-T06 -status: wait +status: done priority: high state_hub_task_id: "39dc383c-7213-495d-8e12-58e614706afe" ``` @@ -251,7 +251,7 @@ open `tenant:platform` and `tenant:coulomb` administration were both denied. ```task id: USER-WP-0020-T08 -status: wait +status: done priority: medium state_hub_task_id: "ecbdeef3-a0a9-40d6-9722-5cc650d78a49" ``` @@ -261,3 +261,24 @@ passes. Record enterprise federation follow-up triggers: customer demand for SAML/OIDC federation, SCIM, directory synchronization, just-in-time provisioning, or customer-owned identity lifecycle. Do not pre-implement those integrations here. + +## Milestone closure (2026-07-30) + +The production Binky MVP is complete and live. Its API covers verified current +user, registration start/completion, tenant-scoped paginated membership +listing, user creation, provider-neutral provisioning, and suspend/reactivate +lifecycle with structured errors, correlation, idempotency gates, durable +transactions, audit, and outbox records. Its browser journey covers KeyCape +sign-in, provider-owned password setup and MFA, tenant administration, and +CSRF-protected lifecycle management. + +Acceptance evidence includes AAL2 login, platform/unrelated-tenant denial, +provider drift and reconciliation, replay-safe deletion, secret rotation, +database restore, and deployment rollback/roll-forward. Broader invitation and +platform recovery APIs, expanded onboarding/administration UX, automated +outbox delivery, and the full accessibility/provider-outage matrix transfer to +`USER-WP-0021`; they are not silently treated as implemented here. + +Enterprise federation remains trigger-driven. Create a separate implementation +plan only when a tenant requires SAML/OIDC federation, SCIM, directory +synchronization, just-in-time provisioning, or customer-owned lifecycle. diff --git a/workplans/USER-WP-0021-portal-product-expansion.md b/workplans/USER-WP-0021-portal-product-expansion.md new file mode 100644 index 0000000..0dba8d3 --- /dev/null +++ b/workplans/USER-WP-0021-portal-product-expansion.md @@ -0,0 +1,85 @@ +--- +id: USER-WP-0021 +type: workplan +title: "Expand user-engine portal beyond the proven Binky MVP" +domain: communication +repo: user-engine +status: backlog +owner: codex +topic_slug: netkingdom +created: "2026-07-30" +updated: "2026-07-30" +depends_on: + - USER-WP-0020 +state_hub_workstream_id: "ba217f48-5fa5-4178-9c79-73aa225f3f2e" +--- + +# USER-WP-0021 - Portal product expansion + +Preserve deliberately deferred product breadth from `USER-WP-0020` without +holding the proven production MVP open. Activate according to tenant demand. + +## T01 - Complete invitation and platform recovery APIs + +```task +id: USER-WP-0021-T01 +status: todo +priority: high +state_hub_task_id: "342299b8-d9a3-408d-bf0d-914496714d5f" +``` + +Add invitation claim/resend/expiry, platform tenant management and recovery +routes, optimistic concurrency, complete OpenAPI schemas, and durable outbox +delivery/replay/dead-letter operations. + +## T02 - Expand self-service onboarding UX + +```task +id: USER-WP-0021-T02 +status: todo +priority: medium +state_hub_task_id: "dc548cfb-db7c-4cbd-864f-2effeebc3dbd" +``` + +Add invitation acceptance, email-verification status, consent/profile, +tenant-selection, and fully resumable onboarding screens while keeping +password and MFA material on provider-owned surfaces. + +## T03 - Expand administration UX + +```task +id: USER-WP-0021-T03 +status: todo +priority: high +state_hub_task_id: "3e0b41ee-6159-46a4-a9fe-c5b6d714cc2a" +``` + +Add platform tenant creation, first-admin bootstrap, invitation/recovery +management, account removal, and redacted lifecycle-gap diagnostics. + +## T04 - Complete broad security and accessibility conformance + +```task +id: USER-WP-0021-T04 +status: todo +priority: high +state_hub_task_id: "fb59245e-6989-4bd9-b72a-68e53ea9f0af" +``` + +Automate duplicate/expired/replayed invitation, session expiry, provider +outage, partial failure, audit-redaction, keyboard/screen-reader, and +mobile/desktop conformance. Preserve existing cross-tenant and escalation +denial gates. + +## T05 - Trigger enterprise federation planning only on demand + +```task +id: USER-WP-0021-T05 +status: wait +priority: low +state_hub_task_id: "05046780-9625-47c2-8caf-f57e9239c603" +``` + +When a tenant requires SAML/OIDC federation, SCIM, directory synchronization, +just-in-time provisioning, or customer-owned lifecycle, create a dedicated +cross-repository plan against the provider-neutral contracts.