Skip to content

v0.97: Gateway admin accounts, employee roster and employee self-service - #101

Merged
KAVentures merged 30 commits into
mainfrom
feat/gateway-identity-admin
Sep 28, 2026
Merged

KAVentures merged 30 commits into
mainfrom
feat/gateway-identity-admin

Conversation

@KAVentures

@KAVentures KAVentures commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

Summary

This is the v0.97 enterprise identity release, reconciled onto the already-merged v0.96 first-value activation work. It does not replace or revert the v0.96 activation/history/agent functionality.

The Gateway previously had an admin page but no named administrator identities or employee roster. This PR adds:

  • named owner/admin/viewer accounts at /admin;
  • password + TOTP or optional company OpenID Connect sign-in;
  • employee roster and identity-bound personal invitations;
  • identity provenance for enrolled computers;
  • employee /me transparency view of organization-held evidence and recorded reads;
  • optional require-verified/personal-invitation enrollment mode;
  • offboarding and explicit device/employee linkage;
  • customer-controlled SSO configuration and deployment docs.

Security invariants added during reconciliation

  • Sole-owner recovery: normal named administrators still cannot demote/disable/reset the only active owner. The bootstrap credential can reset that owner only when the operator has deliberately left/re-enabled bootstrap-token API access.
  • Per-device SSO proof: one successful SSO confirmation on a personal invitation authorizes one computer enrollment. A multi-device invitation requires a fresh confirmation for each additional computer.
  • Multi-organization /me: if the same email exists in more than one organization on one Gateway, generic company sign-in refuses to guess which tenant to open; an organization-specific/device link is required.
  • OIDC email semantics: an ID token explicitly marked email_verified: false is refused. Providers that omit the optional claim are supported only after normal signature/issuer/audience/nonce verification, optional allowed-domain enforcement, and matching a known administrator or roster employee.
  • Setup/session/invitation secrets used by browser pages travel in URL fragments and are removed from the address bar; pages use CSP/nonces, no-store, and frame denial.

Compatibility

  • PR v0.96: first useful reconstruction without new capture #100 / v0.96 first-useful-reconstruction files are preserved in this branch.
  • Existing admin endpoints, group invitations, managed enrollment, legacy enrollment and already-enrolled devices remain compatible.
  • No change to canonical local evidence, MCP tool contracts, History/Retention, agent ingest, organization sharing ceilings, or export formats.
  • docs/CHANGELOG_V096.md remains the v0.96 activation changelog; this release uses docs/CHANGELOG_V097.md.

Release

All version authorities are aligned to 0.97.0 so, after merge, the release workflow will create a new v0.97.0 release rather than silently leaving the already-published v0.96.0 releases/latest ZIP in place.

Please merge only after the full exact-head Python matrix, browser JS, Gateway/Postgres container, macOS/Windows packages, Claude MCPB and custom-agent SDK packaging are green.

- Named administrator accounts at /admin (owner/admin/viewer), password +
  authenticator (TOTP) or company sign-in; bootstrap token only creates the
  first owner and can be disabled for API use.
- Employee roster (manual or CSV) and personal invitations that lock a
  computer's identity to one employee; identity source per computer;
  linking self-reported computers; require-verified mode; offboarding.
- /me: each employee sees their computers, the evidence the Gateway holds,
  who can read it and every recorded read, opened from their own
  OpenWorkGraph or with company sign-in.
- OpenID Connect sign-in (PKCE, nonce, JWKS-verified ID tokens) for admins,
  employees and invitation confirmation (/join/verify).
- Docs, deploy settings and tests.
v0.96: first useful reconstruction without new capture
Preserve the merged first-value activation work from main while retaining the Gateway named-admin, employee-roster, personal-invitation and employee self-service implementation from PR #101. Resolve the overlapping package-data and v0.96 changelog files deliberately.
@KAVentures KAVentures changed the title Gateway admin accounts, employee roster and the employee's own view v0.97: Gateway admin accounts, employee roster and employee self-service Sep 28, 2026
@KAVentures
KAVentures merged commit ee9c02c into main Sep 28, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant