Auth And Identity Boundary
Status: ACTIVE
Audit Date: 2026-03-16
Cleanup Sprint: 01
Boundary Verdict
- VERIFIED:
services/svc-authis the current canonical owner of auth/session/account runtime for the public platform path.
Resolving locale, route permissions, and workspace projection.
Current scope: Guest
Category: 10_normative | Version: v1.0.0
Owner: DOCUMENT_CUSTODIAN | Review cycle: 90 days
Approval authority: GOVERNANCE_ADMIN
Documentation portal is read-only. Editing and mutation endpoints are disabled.
Kvary platform is originally created in Georgian. Where a Georgian version exists, Georgian is authoritative for platform UI, documentation, and legal interpretation.
Translations into other languages are provided for convenience. Some records may originate in other languages and carry their own source or legal locale for a specific flow, but where a Georgian version is available, the Georgian version prevails for platform-level wording and interpretation.
Metadata incomplete: Document ID, Version, Owner Role, Last Review Date, Next Review Date, Change Log
Status: ACTIVE
Audit Date: 2026-03-16
Cleanup Sprint: 01
services/svc-auth is the current canonical owner of auth/session/account runtime for the public platform path.packages/identity-infra is the current canonical owner of stakeholder onboarding persistence and reviewer workflow implementation.services/api is the public façade for both, but it exposes these capabilities unevenly.svc-auth and identity-infra.Owner: services/svc-auth
State: REAL
Evidence:
Owned concerns:
/meOwner: packages/identity-infra
State: REAL
Evidence:
Owned concerns:
Owner: services/api façade
State: MIXED
Evidence:
/stakeholder-applications/:id/review-start, request-info, approve, reject, verify501 not_implemented in services/api/src/routes/stakeholder-applications.tsImpact:
apps/web
-> services/api
-> services/svc-auth for auth/session/account
-> stakeholder service URL target for onboarding/contextsvc-auth as canonical for auth/session/account.identity-infra as canonical for stakeholder application data and reviewer workflow implementation.services/api as façade only, not canonical owner of either domain.Reason:
Founder / architecture decision needed:
Option A:
Keep identity-infra as canonical stakeholder workflow runtime and proxy the missing reviewer actions from services/api.
Option B: Migrate stakeholder onboarding/runtime into a dedicated canonical service and retire backend overlap.
Current recommendation: