ADR-012: User Authentication Strategy
[SUPERSEDED by ADR-016 and ADR-017] Dual-mode auth — GitHub OAuth with org-gate for internal admins, email magic link with whitelist for early clients
[SUPERSEDED by ADR-016 and ADR-017] Dual-mode auth — GitHub OAuth with org-gate for internal admins, email magic link with whitelist for early clients
Step-by-step setup guide for new developers joining SecurityV0
Proposal for automating source system provisioning across Azure, AWS, GCP, and ServiceNow using Terraform modules for cloud identity and per-connector Python setup scripts for SaaS configuration
How SecurityV0 decides whether a thing is an identity (principal), a permission grouping (role / permission_set), a permission, or a resource — by behavior, not by the word a vendor uses. Includes the litmus test and a cross-system mapping table (AWS, Entra ID, ServiceNow, GitHub, Kubernetes). Read this whenever a type label looks wrong.
Founder direction on whether a stronger SecurityV0 overview page is a priority now, with explicit guidance on which Wiz-inspired patterns are core versus deferrable.
Bridge document between what connectors discover and what the platform stores and evaluates. Read this before setting up a dev environment, debugging connector output, or explaining the system to a non-developer.