Identity stays bounded
Account, tenant, and synchronization authority remain separate so a convenient entry path does not become a broad grant.
Enterprise foundations
Cinch approaches enterprise readiness as a set of bounded capabilities. Each public claim carries a maturity level, exact scope, and the limits that still remain.
operator-approved public claims
Operating principles
The goal is not to collect enterprise labels. It is to make identity, access, governance, and lifecycle behavior inspectable without exposing private implementation material.
Account, tenant, and synchronization authority remain separate so a convenient entry path does not become a broad grant.
Membership, guest collaboration, sessions, and administrative authority are treated as current state—not permanent assumptions.
Important changes carry explicit authority, reviewable evidence, and known limits instead of an undifferentiated “enterprise ready” badge.
Export, audit, retention, and recovery claims are kept distinct so each can be evaluated at its actual maturity.
An operating program
It is the continuing work of permission design, realistic validation, controlled change, recovery practice, operating evidence, and claims that never outrun their proof.
Identity, tenant, session, synchronization, and administrative authority are distinct responsibilities—not interchangeable conveniences.
Critical contracts are exercised against realistic state, permissions, and failure conditions instead of inferred from feature presence.
Change carries health evidence, a controlled promotion path, an explicit blast radius, and a known way back.
Designed, implemented, validated, and exercised remain different claims, with unresolved work visible beside the evidence.
Approved capability evidence
These entries are synchronized from the application evidence registry only after an operator approves the exact wording. Local validation is not presented as production exercise.
Cinch can invite an external guest directly into one selected public or private channel while preserving single-use credentials, tenant-bound authorization, and channel-exact access.
Teams can collaborate with clients, contractors, partners, and vendors in a deliberately scoped room without exposing the whole workspace or introducing cross-tenant credentials and trust.
New guest invitations require one active named channel; redemption rechecks and grants only that membership. A composite tenant foreign key, RLS, safe pending metadata, recipient binding, legacy-link fallback, and existing guest permissions preserve the boundary. Focused tests, both type checks, lint, schema drift, build, and the 238-file/1,887-test suite pass. CI, release, and production exercise remain pending; the approved wording is bounded to validated capability.
Application releases use a blue/green strategy. The complete replacement web fleet and fresh SBOM-backed image policy must pass before traffic is promoted, the prior image is retained as rollback evidence, and routine application releases leave the real-time sync service unchanged.
Health-gated promotion reduces release risk for authenticated customers while separating routine product delivery from maintenance on the stateful real-time sync tier.
Releases on 2026-08-10 exercised healthy replacement Machines, immutable identity, public checks, the private Zero hop, and unchanged Zero. On 2026-08-11 refreshed vulnerability data blocked two candidates without an exception or promotion. Later, evidence-backed OpenSSL dispositions yielded zero blocked findings; source 70e27f0ffa484fc0964f0672fc08a567d058adb0 passed the same gate, promoted two healthy Machines, passed all twelve public checks, and left Zero unchanged. Active-session continuity remains an evidence gap, so zero-interruption wording is not approved.
See the boundary