ContractSpec docs

OSS-first docs

These docs teach the open system first: contracts, generated surfaces, runtimes, governance, and incremental adoption. Studio shows up as the operating layer on top, not as the source of truth.

Feature Hubs

Auth Admin Hub

Manage organizations, roles, invitations, SSO, SCIM, domains, posture, and tenant audit.

Explicit admin

Every route and operation requires a declared administrative capability.

Shared identity

User and admin Hubs share canonical AuthOS identity/session contracts, not implicit authority.

Copy-ready example

import { installAuthAdminHub } from "@lssm-tech/module.auth-os/hub";

const hub = await installAuthAdminHub({
  context,
  ports: yourProviderNeutralPorts,
  evaluatePolicy: (policyId, operationRef) =>
    policyEngine.evaluate({ policyId, operationRef, context }),
  fulfillPolicyObligations: (request) => obligationRuntime.fulfill(request),
});
await hub.start();

Production truth

Deterministic fixtures, adapters, and provider templates remain candidate. Qualified means the consumer has passed live provider, infrastructure, security, restore, failover, canary, rollback, and operator qualification in the exact environment.

Related package reference

Runnable all-nine reference app