Block a user
[Feature] Define typed event envelope
[Feature] Add UI tests for blocked/disallowed lower-level policy choices
[Feature] Define frontend effective-policy component contract
[Feature] Define backend explain endpoint shape
[Feature] Define policy source path format
[Feature] Define shared
PolicyDecision
[Task] Inventory current mail, retention, RBAC, delegation, and governance policy logic
[Feature] Create extraction checklist for models, migrations, routes, services, WebUI pages, and tests
[Feature] Define access module manifest target
[Feature] Define
PrincipalResolver protocol in kernel
[Task] Identify which imports belong to future
govoplan-access
[Task] Inventory all current
govoplan_core.access, auth, user, account, group, API key, role, and permission imports
[Feature] Keep compatibility imports documented before extraction begins
[Feature] Add manifest schema/version validation
[Feature] Add backend startup tests for supported module permutations
[Feature] Add a dependency-boundary test or lint script
[Feature] Add "kernel must not own product semantics" as an architecture rule
[Task] Write a concise kernel responsibility statement in
MODULE_ARCHITECTURE.md
[Task] Operations governance dashboard
[Task] Destructive tenant erasure orchestration