mirror of
https://github.com/Memo-2023/mana-monorepo.git
synced 2026-05-14 22:21:10 +02:00
Write up the design for a repo-wide visibility layer before building. Today the state is fragmented: 7 modules carry ad-hoc isPublic booleans (picture, cards, presi, memoro, times, broadcast.audience, uload.tags) with inconsistent semantics and mostly no UI; the majority of modules (library, calendar, todo, places, events, recipes, goals, habits, quiz, wardrobe, invoices-clients, …) have nothing. Spaces only carry member permissions, no public tier. The existing encryption layer (27 encrypted tables) is not a blocker — embeds.ts already demonstrates "decrypt client-side, inline plaintext into the publish snapshot". Design: - @mana/shared-privacy package with `VisibilityLevel = 'private' | 'space' | 'unlisted' | 'public'`, a `<VisibilityPicker>` svelte component, and predicate helpers (canEmbedOnWebsite, isVisibleToSpaceMember, …) - Per-record `visibility text not null default 'private'` on public-capable tables only; `unlistedToken`, `visibilityChangedAt`, `visibilityChangedBy` alongside. Field stays plaintext so RLS + publish resolvers can read it without the user's master key - Default-per-space-type: personal → private, team/club → space. Never public/unlisted by default - Embed resolvers gate hard on `canEmbedOnWebsite`; user filters (tags, status, date window) stack on top, never replace - RLS predicate extended: `space_member OR visibility='public' OR (visibility='unlisted' AND unlisted_token matches header)` Rollout (soft-first / hard-follow-up per existing migration convention): M1 shared package · M2 library (pilot) · M3 picture (replaces isPublic) · M4 calendar + todo + goals · M5 places/events/recipes/habits/quiz/wardrobe /invoices · M6 legacy-flag consolidation · M7 /settings/privacy overview + kill-switch · M8 (optional) unlisted share links. Out of scope: per-user sharing, field-level visibility, visibility cascading, time-boxed public, search-indexing by default. Documented explicitly so the first implementer doesn't reopen these. No code yet — waiting on user go-ahead before starting M1. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| agent-loop-improvements-m1.md | ||
| ai-mission-key-grant.md | ||
| articles-homepage.md | ||
| articles-module.md | ||
| broadcast-module.md | ||
| data-export-v2.md | ||
| destructive-tools-opt-in.md | ||
| event-discovery.md | ||
| invoices-module.md | ||
| library-module.md | ||
| mail-module-plan.md | ||
| mana-mcp-and-personas.md | ||
| mana-research-service.md | ||
| me-images-and-reference-generation.md | ||
| me-images-space-scope-migration.md | ||
| multi-agent-workbench.md | ||
| news-research-module.md | ||
| onboarding-flow.md | ||
| per-space-vs-user-global-tags.md | ||
| planner-function-calling.md | ||
| README.md | ||
| scene-scope-empty-state.md | ||
| shared-space-smoketest.md | ||
| social-relay-module.md | ||
| space-scoped-data-model.md | ||
| spaces-foundation.md | ||
| team-workbench.md | ||
| tipps-module.md | ||
| visibility-system.md | ||
| wardrobe-module.md | ||
| website-builder-smoketest.md | ||
| website-builder.md | ||
| workbench-cards-migration.md | ||
| workbench-templates.md | ||
Plans
Design + rollout plans, grouped by topic. Plans are long-form docs with baked-in decisions, phasing, open questions, and (when shipped) a history section with commit refs.
AI / Workbench roadmap
The Mana AI Workbench has evolved in three successive planned waves — each one laying foundations the next one relies on:
User hat einen Companion (v0 — shipped before these docs)
│
▼
AI Missions + Proposals + Policy + Revert
│
▼
Mission Key-Grants ← ai-mission-key-grant.md ✅
(encrypted inputs decryptable by the server runner)
│
▼
Multi-Agent Workbench ← multi-agent-workbench.md ✅
(named agents, per-agent policy/memory/budget,
identity-aware Actor, scene→agent lens)
│
▼
Team Workbench ← team-workbench.md 📝 (not started)
(multi-user + shared AI context,
admin lens on team members)
| Plan | Status | Scope |
|---|---|---|
ai-mission-key-grant.md |
✅ Shipped | Per-mission RSA-wrapped key grant so mana-ai can decrypt allowlisted encrypted records when user opts in. |
multi-agent-workbench.md |
✅ Shipped | Identity-aware Actor + named AI agents owning missions + per-agent policy + scene lens. 28 tools across 11 modules including server-side web-research. |
workbench-templates.md |
✅ T1 Shipped | Generalised templates: 3 agent-templates + 3 non-AI workbench starter-kits. Seed-handler registry for per-module data seeding. |
team-workbench.md |
📝 Forward-looking | TeamSpace with membership, team-encrypted records, admin lens on team members. Reuses Actor.principalId + key-wrapping patterns from the two above. |
Cross-references:
- Architecture narrative:
docs/architecture/COMPANION_BRAIN_ARCHITECTURE.md§20 (AI Workbench base), §21 (Mission Grants), §22 (Multi-Agent), §23 (Reasoning Loop + Research + Debug) - Non-plan ideas backlog:
docs/future/AI_AGENTS_IDEAS.md - Service-internal notes:
services/mana-ai/CLAUDE.md - Webapp-internal notes:
apps/mana/CLAUDE.md→ "AI Workbench" section
Other plans
| Plan | Topic |
|---|---|
mail-module-plan.md |
Mail module — IMAP/SMTP integration |
news-research-module.md |
News + research pipeline |