You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Successor to #2696 (ADR-0090 tracking — now fully delivered and closed). This issue carries the six named follow-up ADRs that ADR-0090 §"Non-goals and named follow-ups" acknowledged and deliberately scoped out of the v2 launch window. None of them changes the v2 breaking surface; each has a workable substitute today.
Convention: per the repo's ADR discipline, the ADR for each item is opened when the work actually starts — this issue is the parking lot, not a commitment to write six documents up front.
2. Segregation of Duties (SoD) — declarative conflict rules between permission sets ("vendor-create must not combine with payment-approve"), checked at assignment time, with an audit report. Joins the D7 lint family. Today's substitute: org process / manual audit.
3. Scale & reorg hardening — membership-set materialization/caching, asynchronous share recalculation, batched BU-subtree moves. Hard gate: 100k-user × 10M-record benchmark — without it, D6 explain/matrix don't hold at enterprise scale. The most engineering-debt-like of the six. Today's substitute: per-request resolution, fine at current tenant sizes. Note: the benchmark's stated blocker (unbounded telemetry, ADR-0057 lifecycle P1–P4, ADR-0057 data lifecycle P1–P4: retention contract, rotation, separation, governance (tracking) #2786) closed completed 2026-07-11 — no hard precondition remains.
4. ERP dimension restrictions — declarative "rows where field ∈ my values" (Frappe User-Permissions shape) as first-class metadata; admin picks dimension values in the UI, platform compiles the row filter. Today's substitute: hand-written RLS/CEL.
5. ALM / environment promotion — export/import + semantic diff of positions/bindings across dev→test→prod, reusing the D6 access-matrix as the diff layer (two environment snapshots subtracted = promotion pre-flight report). Today's substitute: manual reconfiguration per environment.
6. Portal identity & licensing — the product track that activates D11 (externalSharingModel) at scale: external registration/auth (separate identity pool vs invite), external-seat licensing/metering. Mechanism is fully shipped (spec shape, runtime enforcement, Studio dial); this is the productization decision. Today's substitute: D11 mechanism usable ad hoc; no external identity product. Note: the kernel-chain posture ladder (tracking(authz): 双轨赛道下的授权改进开发任务 v2(内核链 ADR 待编号 + 补齐轨 + 地基) #2920 B2, ADR-0095 D2) reserves an EXTERNAL rung with locked semantics; item 6 itself has not started.
Suggested priority (non-binding)
#3 (hard benchmark gate) and #1 (compliance + the D10 agent-grant substrate) are the likeliest first pulls; #6 activates whenever the portal product track starts. #2/#4/#5 are demand-driven. 2026-07-15: #1 pulled and delivered (community scope, see above). #3's precondition is now clear.
References
ADR-0090: docs/adr/0090-permission-model-v2-concept-convergence.md §"Non-goals and named follow-ups"
Successor to #2696 (ADR-0090 tracking — now fully delivered and closed). This issue carries the six named follow-up ADRs that ADR-0090 §"Non-goals and named follow-ups" acknowledged and deliberately scoped out of the v2 launch window. None of them changes the v2 breaking surface; each has a workable substitute today.
Convention: per the repo's ADR discipline, the ADR for each item is opened when the work actually starts — this issue is the parking lot, not a commitment to write six documents up front.
The six follow-ups
valid_from/valid_until), delegation-of-duty during absence, break-glass elevation with auto-expiry, periodic access-review campaigns (SOX/等保). Also the substrate for task-scoped, time-boxed AI-agent grants (D10) — the agent story is a second trigger for this one.Today's substitute: permanent grants + manual review.
→ Delivered (community scope): ADR-0091 Accepted (docs(adr): ADR-0091 (Proposed) — grant lifecycle: effective-dated assignments, delegation, break-glass, recertification substrate #2751 proposed, docs(adr): ADR-0091 accepted — grant lifecycle decisions confirmed; D3 gains the no-self-renewal rule #2764 accepted). L1 validity windows + resolution-time filtering merged (feat(security): ADR-0091 L1 — grant validity windows with resolution-time filtering #2795); L2 delegation-of-duty merged (feat(security): ADR-0091 L2 — delegation of duty (职务代理) #2810). Break-glass community shape (time-boxed, reasoned direct grant) is in L1; break-glass activation workflow + recertification campaigns are ADR-0091 L3 (enterprise, cloud-side) — not tracked here.
Today's substitute: org process / manual audit.
Today's substitute: per-request resolution, fine at current tenant sizes.
Note: the benchmark's stated blocker (unbounded telemetry, ADR-0057 lifecycle P1–P4, ADR-0057 data lifecycle P1–P4: retention contract, rotation, separation, governance (tracking) #2786) closed completed 2026-07-11 — no hard precondition remains.
Today's substitute: hand-written RLS/CEL.
Today's substitute: manual reconfiguration per environment.
externalSharingModel) at scale: external registration/auth (separate identity pool vs invite), external-seat licensing/metering. Mechanism is fully shipped (spec shape, runtime enforcement, Studio dial); this is the productization decision.Today's substitute: D11 mechanism usable ad hoc; no external identity product.
Note: the kernel-chain posture ladder (tracking(authz): 双轨赛道下的授权改进开发任务 v2(内核链 ADR 待编号 + 补齐轨 + 地基) #2920 B2, ADR-0095 D2) reserves an
EXTERNALrung with locked semantics; item 6 itself has not started.Suggested priority (non-binding)
#3 (hard benchmark gate) and #1 (compliance + the D10 agent-grant substrate) are the likeliest first pulls; #6 activates whenever the portal product track starts. #2/#4/#5 are demand-driven.
2026-07-15: #1 pulled and delivered (community scope, see above). #3's precondition is now clear.
References
docs/adr/0090-permission-model-v2-concept-convergence.md§"Non-goals and named follow-ups"docs/adr/0091-grant-lifecycle-and-recertification.md— Accepted 2026-07-10🤖 Generated with Claude Code