Block a user
[Feature] Evaluate future POP3/JMAP support after the IMAP mailbox MVP is stable. Prefer JMAP for modern sync/search if a target server supports it; add POP3 only for explicit l...
[Task] Bounce mailbox watching and processing
[Task] S/MIME/OpenPGP signing/encryption with no-silent-downgrade policy
[Task] Require profile reselection/revalidation where ownership transfer changes allowed mail profiles
[Feature] Add connector blacklist/whitelist policy handling
[Feature] Add Nextcloud/WebDAV/SMB connectors later using the same governance and freeze-before-send model
[Task] Avoid live remote file dependency at send time for MVP
[Task] Apply hierarchical allow/deny policy before connector access
[Task] Audit connector access and import actions
[Task] Store source provenance and source revision metadata
[Task] Copy/freeze selected files into managed storage for execution evidence
[Task] Browse libraries/folders/files read-only at first
[Task] Configure connector endpoints and credentials through governance-aware settings
[Feature] Implement governed Seafile connector first
[Task] Review the file rename path without owner context: move remaining callers to the owner-scoped bulk path where possible, or keep the fallback explicitly legacy with regres...
[Task] Decide: How long should core keep compatibility route paths for existing clients?
[Task] Decide: Should audit move before policy provenance, or after access/tenancy are split?
[Task] Decide: Should secret encryption remain a kernel primitive or become an access-owned capability?
[Task] Decide: Which table names must remain stable for painless migrations?
[Task] Decide: Should tenant models move with access first, or should
govoplan-tenancy be created before moving live models?