Enhancement proposals
KEP/RFC-style proposals: the change process for architectural and product
additions — before first implementation they stage the feature backlog against
the implementation arc (each carries a milestone: front-matter field, per
proposal 0001's attachment table); after it, they are the change process for a
running system. Start one by copying template.md into draft/. Accepted
proposals move to accepted/. See ../README.md for how this class relates to
ADRs and the living architecture overview.
Documents
- Proposal: The implementation arc — ordering of when to build what
- Proposal: Milestone 0 — the walking skeleton (implementation plan)
- Proposal: Account recovery and contact verification
- Proposal: Secret handling for non-signing secrets
- Proposal: Build and release-pipeline integrity
- Proposal: Resource-exhaustion and asymmetric-DoS hardening
- Proposal: Hosted login experience and branding (Universal Login)
- Proposal: Token and claims customization
- Proposal: Webhooks and event subscriptions
- Proposal: Self-service account management
- Proposal: Notification delivery (email and SMS)
- Proposal: Observability — telemetry, SLOs, and the security-freshness view
- Proposal: Credential policy and breached-password protection
- Proposal: User migration (bulk and just-in-time)
- Proposal: B2B organizations
- Proposal: Delegated administration
- Proposal: Directory synchronization (inbound AD/LDAP and HR)
- Proposal: Admin console and reporting
- Proposal: Billing and usage metering
- Proposal: Accessibility (WCAG) for the hosted UIs
- Proposal: Attack protection — bot detection, signup fraud, and credential-stuffing defense
- Proposal: Token vault — upstream-IdP token storage and brokerage
- Proposal: Configuration as code and environment promotion
- Proposal: Integration catalog and app templates
- Proposal: Compliance enablement and data residency
- Proposal: Admin impersonation ("log in as user")
- Proposal: SDKs, quickstarts, and developer experience
- Proposal: Authenticator app and push MFA
- Proposal: The release plan — versions, artifacts, and support per milestone
- Proposal: <title>