Docs: spaces & membership handbook — two models, config, optional IdP-write power mode #218

Closed
opened 2026-08-13 15:17:48 +00:00 by Cordy · 0 comments
Owner

Parent: #211. Land as the feature ships (don't document ahead of behaviour).

Update the handbook for the shipped model:

  • spaces.md (or the spaces section): the two kinds of space — read-only IdP-group spaces vs app-owned Cairn spaces — what each is for, how membership works, owner/roles, and the collision rule.
  • deployment.md / config reference: the new group/IdP config block (read client vs write power mode), that app-owned spaces are the default and need no IdP client, and the manage-users blast-radius warning on the power mode.
  • encryption.md: fix the now-stale coupling — the Keycloak admin client is no longer an encryption/custody concern.
  • Cross-link the ADR (#212).

Product-neutral, per the handbook rules. Also feeds the v0.8 doc-refresh (#206).

Parent: #211. Land as the feature ships (don't document ahead of behaviour). Update the handbook for the shipped model: - `spaces.md` (or the spaces section): the two kinds of space — **read-only IdP-group spaces** vs **app-owned Cairn spaces** — what each is for, how membership works, owner/roles, and the collision rule. - `deployment.md` / config reference: the new group/IdP config block (read client vs write power mode), that app-owned spaces are the default and need no IdP client, and the `manage-users` blast-radius warning on the power mode. - `encryption.md`: fix the now-stale coupling — the Keycloak admin client is no longer an encryption/custody concern. - Cross-link the ADR (#212). Product-neutral, per the handbook rules. Also feeds the v0.8 doc-refresh (#206).
Cordy closed this issue 2026-08-13 17:16:00 +00:00
Sign in to join this conversation.
No labels
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: Cordy/Cairn#218
No description provided.