docs(adr): spaces membership — app-owned default, IdP-write optional (#212) #219

Merged
Cordy merged 1 commit from docs-adr-spaces into main 2026-08-13 15:19:59 +00:00
Owner

Records the spaces/membership architecture decision (Option C) as docs/adr/0001-spaces-membership.md, closing #212.

Captures: the current IdP-write coupling and why it doesn't generalise, the three options with a security/trust comparison, the chosen app-owned model (membership in the encrypted state-backend; IdP groups read-only; IdP-write demoted to an optional documented power mode), the industry grounding (Nextcloud, Google/SharePoint, Keycloak's read-vs-write privilege line), consequences, and the #211 rollout order.

Docs only. The ARCHITECTURE.md cross-link rides with the handbook pass (#218).

Records the spaces/membership architecture decision (Option C) as `docs/adr/0001-spaces-membership.md`, closing #212. Captures: the current IdP-write coupling and why it doesn't generalise, the three options with a security/trust comparison, the chosen app-owned model (membership in the encrypted state-backend; IdP groups read-only; IdP-write demoted to an optional documented power mode), the industry grounding (Nextcloud, Google/SharePoint, Keycloak's read-vs-write privilege line), consequences, and the #211 rollout order. Docs only. The `ARCHITECTURE.md` cross-link rides with the handbook pass (#218).
docs(adr): spaces membership — app-owned default, IdP-write optional (#212)
All checks were successful
ci / test-and-build (pull_request) Successful in 34s
83f656d71c
Cordy merged commit 257702207b into main 2026-08-13 15:19:59 +00:00
Cordy deleted branch docs-adr-spaces 2026-08-13 15:20:03 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: Cordy/Cairn#219
No description provided.