Block a user
[Feature] Keep only shell-level admin layout and module aggregation in kernel/core WebUI
[Feature] Move audit admin pages to audit module
[Feature] Move policy admin pages to policy module
[Feature] Move tenant admin pages to tenancy module
[Feature] Move access admin pages to access module
[Feature] Define admin route/nav contribution contract
[Feature] Add evidence bundle export as a later audit capability
[Feature] Add event producers for access, tenancy, policy, files, mail, and campaign actions
[Feature] Move audit log storage/query/export into audit module
[Task] Introduce outbox table and dispatcher for production-safe event delivery
[Task] Separate command bus from event bus
[Feature] Define typed
PlatformEvent envelope with actor, tenant, subject, resource, correlation, causation, classification, and payload
[Feature] Add regression tests for non-viable lower-level options being hidden or disabled
[Feature] Move mail/retention effective policy display onto shared policy components
[Feature] Add policy simulation before destructive/limiting changes
[Feature] Add explain endpoints and UI component contract for policy source paths
[Feature] Move delegation ceilings and "more restrictive only" validation into policy
[Feature] Move hierarchical policy evaluation into policy
[Feature] Add tenant lifecycle tests with files/mail/campaign installed and absent
[Feature] Add delete-veto orchestration through module providers