Initiative Brief: Workspace & Managed-Context Authorization True-Up
COMPLETEDIntent— the specification (1,534 chars); the plan below decomposes it into work items. Click to expand.
# Initiative Brief: Workspace & Managed-Context Authorization True-Up ## Desired outcome Bring Xyence Workspace authorization, Doorway authorization, and Console access-management UI into alignment with the authorization architecture that already exists in Outshine. The primary goal is to make Workspace access fully manageable through first-class UI surfaces while clarifying the architectural distinction between **Workspaces**, **Doorways**, and other authorization scopes. This initiative should **not introduce a new identity system, permission engine, membership store, or authentication architecture**. Outshine remains the canonical source of truth for users, principals, roles, permission grants, and authorization decisions. The implementation should build on the existing `PermissionGrant`, `PermissionRole`, `Principal`, `WorkspaceInstance`, Workspace membership APIs, and `permission_engine.can(...)` machinery. --- ## Rejected / deferred alternatives - Do NOT: - replace the Outshine permission engine, - create a second Workspace permission system, - create a new identity database, - migrate authentication out of Outshine, - build Account Center now, - rewrite `auth.xyence.io`, - turn Workspaces into Doorways, - remove Doorways, - encode Workspace access using Console-local teams, - duplicate permission state in Console, - hard-code the system around Sales, - make `workspace_admin` global, - redesign all authorization scopes in one pass, - undertake unrelated Console navigation or styling refactors. ---
Repository scope
targets the work spans — independent of where the brief was authoredPrimary repository: outshine
- outshineactive · primary
- consolediscovered
- workspacesdiscovered
brief revision 1 assessed as delivered
assessed with 74% confidenceThe initiative’s outcome is achieved end to end. Outshine remains the sole authorization authority (PermissionGrant/PermissionRole/Principal/permission_engine.can) and no parallel identity, membership, or permission system was introduced. The minor API gaps identified in the audit (standalone assignable-role catalog and manageable-only filter) were implemented additively in Outshine (#410). Console now provides a first-class Workspace access-management surface that proxies 100% of reads/writes to Outshine, with UI cues derived from Outshine’s effective permissions and server-side enforcement on every mutation (#168). The UI explicitly separates Workspaces from Doorways in navigation and copy, reinforcing the architectural distinction. Workspaces apps were aligned to defer authorization to Outshine and to carry WorkspaceInstance scope on every request (#84). No deliverable in the brief depends on new engines, schemas, or local duplication, and those invariants are honored. While some server-side behaviors (e.g., audit event writing) are asserted by the Outshine docs rather than re-tested in these diffs, they pre-existed and the delivered UI/API integration consumes them as intended.
Plan waves — 1 approved wave
planning closed- Wave 1completeAPPROVED4 work items
Align Workspace and Doorway authorization with the existing Outshine authorization architecture; make Workspace access fully manageable via first-class Console UI without introducing new identity/auth systems or duplicating permission state. Deliver architecture alignment docs + API audit in Outshine, implement any missing Outshine API affordances for Workspace access management, build Console UI that uses those APIs, and align the Workspaces monorepo apps to consistently use Outshine authorization semantics and WorkspaceInstance scoping.
Work items
| # | Title | Repository | State | Issue | PR / CI | Review | |
|---|---|---|---|---|---|---|---|
| 0 | Authorize scopes alignment doc and API audit for Workspace/Doorway management | outshine | COMPLETED | #409 | #413merged · CI passed | c1: approve | |
| 1 ⛓ | Implement missing API affordances for Workspace access management (reuse existing models/engine) | outshine | COMPLETED | #410 | #414merged · CI passed | c1: approve | |
| 2 ⛓ | Add Workspace access-management UI using Outshine authorization APIs (no local duplication) | console | COMPLETED | #168 | #171merged · CI passed | c1: approve | |
| 3 ⛓ | Align Workspaces apps with Outshine permission_engine.can(...) and WorkspaceInstance scoping | workspaces | COMPLETED | #84 | #90merged · CI passed | c1: approve |
Release candidate
ELIGIBLEAll work complete — merged, reviewed, and unblocked. Release and deployment remain manual.
ec222a3f7a · review approvefa15ec71a5 · review approvee9ee7bf979 · review approve9ec780ca1a · review approveRelease planning
Releases are cut in the Release planning section. Associating this initiative requires an admin role.
Associating an initiative to a release only records the link — it never changes the initiative’s own state or work. Releases are optional.
Timeline
No events yet.