ADR: record the spaces-membership decision (app-owned default, IdP-write optional) #212
Labels
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: Cordy/Cairn#212
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Parent: #211.
Record the architecture decision in-repo so the reasoning survives: the two-model design (read-only IdP-group spaces vs app-owned Cairn spaces), why IdP-write is demoted to an optional power mode (blast radius of
manage-users, AD non-starter, separation of duties, sovereignty alignment), the industry grounding (Nextcloud local+LDAP hybrid; Google/SharePoint reference-not-mutate; Keycloak read vs write privilege line), and the security/trust comparison.Deliverable: a decision record next to
IMPLEMENTED-PEERING.md(e.g.docs/adr/0001-spaces-membership.mdorIMPLEMENTED-SPACES.md), linked fromARCHITECTURE.md. Product-neutral. This is the written form of the decision memo from the dogfood session.First sub-issue to land (documents intent before the code).