Enterprise foundations

Control should grow without taking over the work.

Cinch approaches enterprise readiness as a set of bounded capabilities. Each public claim carries a maturity level, exact scope, and the limits that still remain.

ENTERPRISE EVIDENCEClaim by claim
2

operator-approved public claims

DesignedImplementedValidatedExercised
Approval never raises maturity.

Operating principles

Specific controls. Specific evidence.

The goal is not to collect enterprise labels. It is to make identity, access, governance, and lifecycle behavior inspectable without exposing private implementation material.

01

Identity stays bounded

Account, tenant, and synchronization authority remain separate so a convenient entry path does not become a broad grant.

02

Access has a lifecycle

Membership, guest collaboration, sessions, and administrative authority are treated as current state—not permanent assumptions.

03

Governance stays explainable

Important changes carry explicit authority, reviewable evidence, and known limits instead of an undifferentiated “enterprise ready” badge.

04

Data controls preserve context

Export, audit, retention, and recovery claims are kept distinct so each can be evaluated at its actual maturity.

An operating program

Enterprise readiness is not a badge applied when enough settings exist.

It is the continuing work of permission design, realistic validation, controlled change, recovery practice, operating evidence, and claims that never outrun their proof.

01

Bound authority

Identity, tenant, session, synchronization, and administrative authority are distinct responsibilities—not interchangeable conveniences.

02

Validate behavior

Critical contracts are exercised against realistic state, permissions, and failure conditions instead of inferred from feature presence.

03

Recover deliberately

Change carries health evidence, a controlled promotion path, an explicit blast radius, and a known way back.

04

State maturity honestly

Designed, implemented, validated, and exercised remain different claims, with unresolved work visible beside the evidence.

Approved capability evidence

Public wording, bounded to what the proof supports.

These entries are synchronized from the application evidence registry only after an operator approves the exact wording. Local validation is not presented as production exercise.

ADR-067Validated

Channel-scoped external guest invitations

Cinch can invite an external guest directly into one selected public or private channel while preserving single-use credentials, tenant-bound authorization, and channel-exact access.

Why it matters

Teams can collaborate with clients, contractors, partners, and vendors in a deliberately scoped room without exposing the whole workspace or introducing cross-tenant credentials and trust.

Scope and limits

New guest invitations require one active named channel; redemption rechecks and grants only that membership. A composite tenant foreign key, RLS, safe pending metadata, recipient binding, legacy-link fallback, and existing guest permissions preserve the boundary. Focused tests, both type checks, lint, schema drift, build, and the 238-file/1,887-test suite pass. CI, release, and production exercise remain pending; the approved wording is bounded to validated capability.

ADR-001Exercised in production

Health-gated blue/green application releases

Application releases use a blue/green strategy. The complete replacement web fleet and fresh SBOM-backed image policy must pass before traffic is promoted, the prior image is retained as rollback evidence, and routine application releases leave the real-time sync service unchanged.

Why it matters

Health-gated promotion reduces release risk for authenticated customers while separating routine product delivery from maintenance on the stateful real-time sync tier.

Scope and limits

Releases on 2026-08-10 exercised healthy replacement Machines, immutable identity, public checks, the private Zero hop, and unchanged Zero. On 2026-08-11 refreshed vulnerability data blocked two candidates without an exception or promotion. Later, evidence-backed OpenSSL dispositions yielded zero blocked findings; source 70e27f0ffa484fc0964f0672fc08a567d058adb0 passed the same gate, promoted two healthy Machines, passed all twelve public checks, and left Zero unchanged. Active-session continuity remains an evidence gap, so zero-interruption wording is not approved.

See the boundary

Review how Cinch separates trust from convenience.

Security & compliance