Block a user
[Feature] Define tenant deletion and module cleanup/veto contract
[Task] Separate tenant lifecycle from membership/roles
[Feature] Define
TenantResolver protocol
[Task] Inventory tenant model and tenant setting usage
[Task] Identify domain events from access, tenancy, policy, files, mail, campaign
[Feature] Define audit module MVP boundaries
[Feature] Add correlation/causation ID support
[Task] Decide command bus versus event bus API shape
[Feature] Define typed event envelope
[Feature] Add UI tests for blocked/disallowed lower-level policy choices
[Feature] Define frontend effective-policy component contract
[Feature] Define backend explain endpoint shape
[Feature] Define policy source path format
[Feature] Define shared
PolicyDecision
[Task] Inventory current mail, retention, RBAC, delegation, and governance policy logic
[Feature] Create extraction checklist for models, migrations, routes, services, WebUI pages, and tests
[Feature] Define access module manifest target
[Feature] Define
PrincipalResolver protocol in kernel
[Task] Identify which imports belong to future
govoplan-access
[Task] Inventory all current
govoplan_core.access, auth, user, account, group, API key, role, and permission imports