Release summaries
managed-companyos-authos-seed-profiles
Add explicit seed profiles, multi-email AuthOS identity authority, private personal workspaces, and fail-closed OPA/CommunicationOS entitlements.
maintainer
Live seed and bootstrap commands now require an explicit MANAGED_COMPANYOS_SEED_PROFILE. Use lssm-hirly for only LSSM and Hirly; legacy-reference preserves LSSM, CompanyOS, and NDconsulting.
customer
The same account can authenticate with tboutron@lssm.co or theo@tryhirly.com and owns isolated LSSM and Hirly memberships with only OPA and CommunicationOS visible.
maintainer
AuthOS email addresses, membership-email bindings, workspace module entitlements, join policies, and profile-specific receipts are durable authority surfaces. Public signup stays fail-closed until every external evidence reference and Turnstile configuration is present.
