You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
OriginWeave currently defines a governed browser runtime and strong Rust authority primitives, but an enterprise buyer cannot yet administer tenants, identities, managed policies, approvals, sensitive-data access, browser sessions, evidence, incidents, retention, or service objectives through a coherent product surface.
A production enterprise product needs more than safe kernel types. It needs an operator experience that answers:
Who or which workload may delegate this task?
Which origins, actions, models, extensions, connectors, and protected fields are permitted?
Which approval is waiting, why is it required, and what exact side effect will occur?
What happened, which evidence supports it, and which control was applied?
Is the service healthy, within SLO, recoverable, and operating in the contracted region?
This issue owns the enterprise control and experience plane. It composes #10, #27, #28, #199, #200, and #201; it does not replace their runtime/security implementation.
Product surfaces
Deliver the following accessible applications, backed by versioned APIs rather than UI-local authority:
Enterprise Admin Console
Task and Approval Workspace
Evidence and Replay Explorer
Policy and Destination Workspace
Sensitive Data and Secret Access Workspace
Extension and Native Host Workspace
Operations and Incident Console
Customer Audit / Procurement Portal
The user-facing language for every warning, denial, approval, recovery action, and evidence gap must state the next valid action rather than merely reporting an internal state.
Identity and tenancy
Integrate with Keyverse-compatible OIDC/OAuth and SCIM without copying authentication credentials into OriginWeave.
issuer, audience, nonce, token lifetime, and signature verification;
tenant and organization membership;
role and attribute policy;
workload/service identity for machine calls;
device/session risk where configured;
just-in-time provisioning and SCIM deprovisioning;
explicit support access, disabled by default;
maker-checker administration for high-risk policy, keys, export, refund/credit-like adjustments if billing integration is later enabled, and break-glass access;
no email-address-only account merging;
no cross-tenant access through administrator, support, cache, queue, object store, search, vector, audit, or model boundaries.
OriginWeave person/workload references remain opaque links. Keyverse owns authentication and credential lifecycle; OriginWeave owns browser-task authorization and evidence.
Authorization and managed policy
Provide versioned, effective-dated policy administration for:
session mode and task purpose;
allowed origins and redirect policy;
destination classes, proxies, PAC sources, VPN profiles, and connectors;
protected-data field and business-purpose disclosure;
secret broker use;
extension/native-host admission and Agent grants;
resource budgets;
capture, export, retention, legal hold, and deletion;
human approval and dual control;
browser/distribution release channels; and
emergency disablement.
Policy changes must produce immutable revisions, impact previews, explicit activation windows, rollback/supersession, and complete decision evidence. Draft policy or LLM recommendation never becomes active without the configured authority.
Approval workspace
An approval must preview the exact immutable intent:
R3/R4 actions require the configured human or dual-control approval.
R5 legal consent remains non-delegable.
Approval is bound to the complete action-intent digest and cannot be reused after origin, fields, file, amount, destination, model, policy, or document epoch changes.
Accessibility, keyboard, screen-reader, high-contrast, reduced-motion, mobile, print, and exact-value views are release requirements.
Evidence and audit experience
Provide an Evidence Explorer that keeps fact classes distinct:
trusted instruction
policy decision
browser/network observation
model inference
human approval
action dispatch
post-condition verification
capture artifact
operator annotation
Users must be able to:
trace a result or action to exact evidence and software/policy versions;
compare planned versus observed destination, peer, TLS, HTTP, node, action, and result;
inspect completeness, redaction, retention, and integrity state;
see missing or stale evidence without it being rendered as success;
create incident/correction annotations without rewriting immutable records; and
verify hash chaining or equivalent tamper-evident sequencing.
Raw protected values are not inserted into generic audit, analytics, browser-accessibility labels, screenshots, support bundles, or model history. Authorized reveal/copy/export is a separate policy decision.
Operations and SLOs
Define production SLI/SLO profiles for standalone and enterprise deployment.
Use 3NF for identity links, policy revisions, assignments, approvals, SLOs, controls, and lifecycle. JSON may preserve immutable external payloads but must not hide authorization or tenant enforcement.
Figma, design tokens, and Storybook
Before production UI implementation:
create the OriginWeave Figma file and record the exact Figma File ID in an accepted UI architecture ADR;
define reusable design tokens for typography, spacing, state, risk, evidence, focus, motion, and data visualization;
build a Storybook inventory for every repeated component and state; and
test implementation parity against approved Figma frames.
Required states include loading, empty, partial evidence, stale evidence, access denied, approval required, conflict, policy changed, provider degraded, replay unavailable, incident, and recovery. Every graph/chart must have an exact-value table and export/print representation.
Accessibility and usability acceptance
WCAG 2.2 AA conformance target for all supported operator/customer surfaces.
Keyboard-only completion of task review, approval, denial, evidence inspection, policy comparison, export, and incident response.
Screen-reader announcements must not expose protected values through hidden DOM or accessible labels.
High-risk actions require clear confirmation while preserving efficient reviewed workflows.
UI text explains consequences, expiry, missing evidence, and the next valid action.
Figma and Storybook tests cover responsive, localization, error, empty, loading, policy conflict, and offline/degraded states.
Security, CSAP, and SOC 2 evidence
Create versioned control_evidence_mapping records rather than certification claims.
Map the actual deployed service boundary, assets, identities, encryption, tenant isolation, access control, audit, incident response, change/release management, continuity, data location, and supply chain to current applicable CSAP criteria.
Map product capability, configured control, operating control, collected evidence, management assertion, and independent examination result separately for SOC 2 Trust Services Criteria.
Provide evidence owners, collection cadence, retention, exceptions, and assessor-facing exports.
No UI, README, release note, or sales document may claim CSAP certification or SOC 2 compliance without the valid certification/report for the defined system and period.
Realistic tests
Two tenants with identical external usernames cannot see, infer, approve, search, export, or support-access each other's task/evidence data.
SCIM deprovisioning removes future access without rewriting historical audit attribution.
Policy draft/review/activation/rollback behaves bitemporally and produces deterministic impact/evidence.
Maker-checker prevents self-approval for configured high-risk changes.
Approval intent mutation, stale document epoch, expired approval, wrong origin, wrong field, wrong file, wrong model, and replay fail closed.
Backup/restore, regional failover, key rotation, deletion, legal hold, and disaster recovery are rehearsed against realistic tenant data.
Queue saturation, provider outage, browser crash, updater failure, and database/object-store degradation produce truthful SLO and incident states.
Keyboard and assistive-technology journeys complete approval, policy, evidence, export, and incident workflows.
Storybook interaction/visual/accessibility tests and Figma parity checks pass for every declared component/state.
Tenant policy, approval, audit, and operations production function/line/region/branch coverage is exactly 100%; public APIs are fully documented; no required E2E/security/accessibility test is skipped.
Use synthetic or explicitly approved anonymized fixtures. Production identities, institutions, or customer data must not enter source, tests, ADRs, screenshots, or demos.
building a second identity provider instead of Keyverse integration;
giving UI code direct database, browser, secret, or policy authority;
treating documentation presence as an operating control;
blanket PII masking that prevents authorized work;
claiming certification from unit tests alone;
making inferred/model-generated findings authoritative without review.
Commercial proof
A regulated enterprise administrator can provision identities, define and review policy, approve an exact high-risk action, operate the runtime against SLOs, investigate and replay evidence, export a control package, and recover from an incident—while a second tenant and unauthorized support user remain unable to access the data or authority.
Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST Special Publication 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207
Chandramouli, R., & Butcher, Z. (2023). A zero trust architecture model for access control in cloud-native applications in multi-cloud environments (NIST Special Publication 800-207A). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207A
Buyer-visible gap
OriginWeave currently defines a governed browser runtime and strong Rust authority primitives, but an enterprise buyer cannot yet administer tenants, identities, managed policies, approvals, sensitive-data access, browser sessions, evidence, incidents, retention, or service objectives through a coherent product surface.
A production enterprise product needs more than safe kernel types. It needs an operator experience that answers:
This issue owns the enterprise control and experience plane. It composes #10, #27, #28, #199, #200, and #201; it does not replace their runtime/security implementation.
Product surfaces
Deliver the following accessible applications, backed by versioned APIs rather than UI-local authority:
The user-facing language for every warning, denial, approval, recovery action, and evidence gap must state the next valid action rather than merely reporting an internal state.
Identity and tenancy
Integrate with Keyverse-compatible OIDC/OAuth and SCIM without copying authentication credentials into OriginWeave.
Required identity classes:
Required controls:
OriginWeave person/workload references remain opaque links. Keyverse owns authentication and credential lifecycle; OriginWeave owns browser-task authorization and evidence.
Authorization and managed policy
Provide versioned, effective-dated policy administration for:
Policy changes must produce immutable revisions, impact previews, explicit activation windows, rollback/supersession, and complete decision evidence. Draft policy or LLM recommendation never becomes active without the configured authority.
Approval workspace
An approval must preview the exact immutable intent:
Required states:
Evidence and audit experience
Provide an Evidence Explorer that keeps fact classes distinct:
Users must be able to:
Raw protected values are not inserted into generic audit, analytics, browser-accessibility labels, screenshots, support bundles, or model history. Authorized reveal/copy/export is a separate policy decision.
Operations and SLOs
Define production SLI/SLO profiles for standalone and enterprise deployment.
Minimum SLIs:
The console must expose:
Do not put tenant IDs, personal data, prompt/response text, secrets, URLs with credentials, or high-cardinality protected values in metric labels.
Deployment and data residency
Support modular deployment profiles:
Data model
Every database object must contain at least two words and use
snake_case. Suggested objects:Use 3NF for identity links, policy revisions, assignments, approvals, SLOs, controls, and lifecycle. JSON may preserve immutable external payloads but must not hide authorization or tenant enforcement.
Figma, design tokens, and Storybook
Before production UI implementation:
Required component inventory includes:
Required states include loading, empty, partial evidence, stale evidence, access denied, approval required, conflict, policy changed, provider degraded, replay unavailable, incident, and recovery. Every graph/chart must have an exact-value table and export/print representation.
Accessibility and usability acceptance
Security, CSAP, and SOC 2 evidence
Create versioned
control_evidence_mappingrecords rather than certification claims.Realistic tests
Use synthetic or explicitly approved anonymized fixtures. Production identities, institutions, or customer data must not enter source, tests, ADRs, screenshots, or demos.
Dependencies and non-goals
Dependencies:
Non-goals:
Commercial proof
A regulated enterprise administrator can provision identities, define and review policy, approve an exact high-risk action, operate the runtime against SLOs, investigate and replay evidence, export a control package, and recover from an incident—while a second tenant and unauthorized support user remain unable to access the data or authority.
Standards and authoritative references — APA 7th
World Wide Web Consortium. (2024). Web Content Accessibility Guidelines (WCAG) 2.2. https://www.w3.org/TR/WCAG22/
Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST Special Publication 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207
Chandramouli, R., & Butcher, Z. (2023). A zero trust architecture model for access control in cloud-native applications in multi-cloud environments (NIST Special Publication 800-207A). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207A
American Institute of Certified Public Accountants. (2023). 2017 trust services criteria for security, availability, processing integrity, confidentiality, and privacy (with revised points of focus—2022). https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022
Korea Internet & Security Agency. (n.d.). 클라우드서비스 보안인증제 제도소개. https://isms.kisa.or.kr/main/csap/intro/index.jsp