Create initiative

Initiative Brief: Workspace & Managed-Context Authorization True-Up

COMPLETED
Intent— the specification (1,534 chars); the plan below decomposes it into work items. Click to expand.

# Initiative Brief: Workspace & Managed-Context Authorization True-Up ## Desired outcome Bring Xyence Workspace authorization, Doorway authorization, and Console access-management UI into alignment with the authorization architecture that already exists in Outshine. The primary goal is to make Workspace access fully manageable through first-class UI surfaces while clarifying the architectural distinction between **Workspaces**, **Doorways**, and other authorization scopes. This initiative should **not introduce a new identity system, permission engine, membership store, or authentication architecture**. Outshine remains the canonical source of truth for users, principals, roles, permission grants, and authorization decisions. The implementation should build on the existing `PermissionGrant`, `PermissionRole`, `Principal`, `WorkspaceInstance`, Workspace membership APIs, and `permission_engine.can(...)` machinery. --- ## Rejected / deferred alternatives - Do NOT: - replace the Outshine permission engine, - create a second Workspace permission system, - create a new identity database, - migrate authentication out of Outshine, - build Account Center now, - rewrite `auth.xyence.io`, - turn Workspaces into Doorways, - remove Doorways, - encode Workspace access using Console-local teams, - duplicate permission state in Console, - hard-code the system around Sales, - make `workspace_admin` global, - redesign all authorization scopes in one pass, - undertake unrelated Console navigation or styling refactors. ---

created 8/9/2026, 3:57:40 PMby human:workspaces-orchestrator-app

Repository scope

targets the work spans — independent of where the brief was authored

Primary repository: outshine

  • outshineactive · primary
  • consolediscovered
  • workspacesdiscovered

brief revision 1 assessed as delivered

assessed with 74% confidence

The initiative’s outcome is achieved end to end. Outshine remains the sole authorization authority (PermissionGrant/PermissionRole/Principal/permission_engine.can) and no parallel identity, membership, or permission system was introduced. The minor API gaps identified in the audit (standalone assignable-role catalog and manageable-only filter) were implemented additively in Outshine (#410). Console now provides a first-class Workspace access-management surface that proxies 100% of reads/writes to Outshine, with UI cues derived from Outshine’s effective permissions and server-side enforcement on every mutation (#168). The UI explicitly separates Workspaces from Doorways in navigation and copy, reinforcing the architectural distinction. Workspaces apps were aligned to defer authorization to Outshine and to carry WorkspaceInstance scope on every request (#84). No deliverable in the brief depends on new engines, schemas, or local duplication, and those invariants are honored. While some server-side behaviors (e.g., audit event writing) are asserted by the Outshine docs rather than re-tested in these diffs, they pre-existed and the delivered UI/API integration consumes them as intended.

Plan waves — 1 approved wave

planning closed
  1. Wave 1completeAPPROVED4 work items

    Align Workspace and Doorway authorization with the existing Outshine authorization architecture; make Workspace access fully manageable via first-class Console UI without introducing new identity/auth systems or duplicating permission state. Deliver architecture alignment docs + API audit in Outshine, implement any missing Outshine API affordances for Workspace access management, build Console UI that uses those APIs, and align the Workspaces monorepo apps to consistently use Outshine authorization semantics and WorkspaceInstance scoping.

Work items

#TitleRepositoryStateIssuePR / CIReview
0Authorize scopes alignment doc and API audit for Workspace/Doorway managementoutshineCOMPLETED#409#413merged · CI passedc1: approve
1 ⛓Implement missing API affordances for Workspace access management (reuse existing models/engine)outshineCOMPLETED#410#414merged · CI passedc1: approve
2 ⛓Add Workspace access-management UI using Outshine authorization APIs (no local duplication)consoleCOMPLETED#168#171merged · CI passedc1: approve
3 ⛓Align Workspaces apps with Outshine permission_engine.can(...) and WorkspaceInstance scopingworkspacesCOMPLETED#84#90merged · CI passedc1: approve

Release candidate

ELIGIBLE

All work complete — merged, reviewed, and unblocked. Release and deployment remain manual.

outshinePR #413 · merged ec222a3f7a · review approve
outshinePR #414 · merged fa15ec71a5 · review approve
consolePR #171 · merged e9ee7bf979 · review approve
workspacesPR #90 · merged 9ec780ca1a · review approve

Release planning

Releases are cut in the Release planning section. Associating this initiative requires an admin role.

Associating an initiative to a release only records the link — it never changes the initiative’s own state or work. Releases are optional.

Timeline

No events yet.

    ← All initiatives