Skip to content

Roadmap & TODO

This is the unified TODO. Update it every session (the goal: one place, here). The detailed master list also lives in agent memory (project_todos_master); this page is the human-readable front.

ItemStatus
Gap #7 — internal admin permission enforcementDesign complete (docs/2026-06-22-gap7-...); implement after the sequential test pass. ⭐ top priority
Developer docs portalThis site. Coverage filled from code; verification ongoing.
Doc consolidation (this page’s purpose)Unify into the portal; archive only 100%-verified-redundant docs/ files as backup (per-file diff + update MEMORY links first). No mass delete.
Reporting / Teams E2ECode merged + dev-deployed (#796–802); manual E2E remaining.
Korean Identity + PaymentPortOne webhook gaps (signature verify / Track B / payment path) before Bullmark v1.
ItemStatus
OpenAPI auto-injectionFeed /openapi/v1.json into the Reference tab so endpoint detail stays in sync with code.
SAML real-IdP E2ECode merged; live cross-vendor interop test outstanding.
Account switching — switch E2ELink verified live; passkey step-up switch needs a passkey test.
Remaining doc pagesMeetings, Inbound, IdP-requests, ConnectedId-mapping (minor).
Cloudflare AccessLock the whole docs site (preserves internal detail privately). Dashboard step.
  • M2M API keys → workload-identity federation (remove static secrets).
  • GRC / Risk register dashboard (enterprise table-stakes).
  • Scalability track (serverless Postgres).
  • Every session: update this page (and the affected reference/concept pages) as work lands.
  • Deep design rationale / handoffs / strategy stay in docs/ (the engineering archive) — indexed from Internal docs.
  • What’s reflected here is the developer-facing summary; the archive holds the full detail.