Block a user
[Feature] Define tenant lifecycle events: created, suspended, resumed, deletion requested, erasure completed
[Feature] Define
TenantResolver and tenant-context protocols in the kernel
[Feature] Keep memberships and role assignments in access
[Feature] Move tenant registry, tenant settings, tenant lifecycle, tenant switching, and tenant deletion orchestration into tenancy
[Feature] Ensure core-only startup still works enough to show shell/health, but access is required for authenticated product use
[Feature] Define
PrincipalResolver and related protocols in the kernel
[Feature] Move login/session/admin access UI into access/admin module contributions
[Feature] Move access migrations into the access module migration registration
[Feature] Move access permissions and default role templates into the access manifest
[Feature] Keep compatibility imports under
govoplan_core.access.* temporarily with deprecation warnings
[Feature] Move accounts, authentication, sessions, API keys, groups, memberships, roles, role assignments, and principal resolution into access
[Feature] Add manifest schema/versioning
[Feature] Add OpenAPI/route collision validation
[Feature] Add a documented deprecation policy for kernel API changes
[Feature] Add contract tests for manifests, route aggregation, migration registration, and capability discovery
[Feature] Move or clearly mark these as kernel-stable contracts:
[Task] Mark DataGrid work as explicitly deferred
[Feature] Keep generated WebUI/test artifacts ignored
[Feature] Keep module-matrix tests for core-only, files-only, mail-only, campaign-only, campaign+files, campaign+mail, full product
[Feature] Add dependency-boundary checks that forbid direct optional module imports