Enterprise roadmap¶
The current foundation establishes the security boundary: authenticated one-key/one-Runtime registration, signed atomic policy/config generations, sticky local enforcement, independently authenticated app-ui/app-api, and a static public API reference/demo.
Later work remains separate and must not be inferred as available:
- OIDC/SSO and organization RBAC;
- durable database selection, backup and migration;
- signing-key rotation and staged/cohort governance rollout;
- optional Runtime OpenTelemetry audit export;
- SaaS audit storage/search and app-api query integration;
- licensing and broader tenant administration.
Runtime continues to work fully in Community/local mode without any of these or without a Control Plane.
Operational examples on this site were verified against Runtime 0.9.8. After bootstrap, the version-exact files in Runtime Home win.