Skip to content

Enterprise roadmap

The current foundation establishes the security boundary: authenticated one-key/one-Runtime registration, signed atomic policy/config generations, sticky local enforcement, independently authenticated app-ui/app-api, and a static public API reference/demo.

Later work remains separate and must not be inferred as available:

  • OIDC/SSO and organization RBAC;
  • durable database selection, backup and migration;
  • signing-key rotation and staged/cohort governance rollout;
  • optional Runtime OpenTelemetry audit export;
  • SaaS audit storage/search and app-api query integration;
  • licensing and broader tenant administration.

Runtime continues to work fully in Community/local mode without any of these or without a Control Plane.

Operational examples on this site were verified against Runtime 0.9.8. After bootstrap, the version-exact files in Runtime Home win.