Design documents
The brief that this site is built from, what it got wrong, and the four documents that carry the reasoning. Copied in verbatim; the markdown is the source of truth and the HTML is rendered from it on every release.
- Brief corrections: What the brief got wrong or left open, found while building, dated, beside it. (markdown)
- Risk Mandate — AWS Cognito Client-Side Architecture: The AWS variant; why no secret can live inside an identity provider; the attack table. (markdown)
- Risk Mandate — GCP Key Vault Architecture & Password Manager MVP: The primary design: all-GCP stack, keyring, PRF unlock, sharing scheme, storage layout, threat summary, password-manager MVP scope. (markdown)
- Risk Mandate — User Onboarding & Account Experience: The Workspace-based onboarding design, the Google terms research, and the five-tier model that led here. (markdown)
- Risk Mandate — Google Workspace as Identity, Storage and Deployment Substrate: The earlier Workspace architecture briefing. (markdown)
- secrets.sgit.ai — MVP build brief: The instruction set: architecture, environments, the site, the keyring specification, the pipeline, the build order. (markdown)