TenantAtlas/.github/agents/copilot-instructions.md
2026-03-18 13:56:09 +01:00

12 KiB

TenantAtlas Development Guidelines

Auto-generated from all feature plans. Last updated: 2025-12-22

Active Technologies

  • PHP 8.4.15 + Laravel 12, Filament v4, Livewire v3 (feat/005-bulk-operations)

  • PostgreSQL (app), SQLite in-memory (tests) (feat/005-bulk-operations)

  • PostgreSQL (Sail locally) (feat/032-backup-scheduling-mvp)

  • PHP 8.4.x + Laravel 12, Filament v4, Livewire v3 (feat/042-inventory-dependencies-graph)

  • PostgreSQL (JSONB) (feat/042-inventory-dependencies-graph)

  • PHP 8.4.x (Laravel 12) + Laravel 12, Filament v4, Livewire v3 (feat/047-inventory-foundations-nodes)

  • PostgreSQL (JSONB for InventoryItem.meta_jsonb) (feat/047-inventory-foundations-nodes)

  • PostgreSQL (JSONB in operation_runs.context, operation_runs.summary_counts) (056-remove-legacy-bulkops)

  • PHP 8.4.15 (Laravel 12.47.0) + Filament v5.0.0, Livewire v4.0.1 (058-tenant-ui-polish)

  • PHP 8.4 (per repo guidelines) + Laravel 12, Filament v5, Livewire v4 (067-rbac-troubleshooting)

  • PostgreSQL (via Laravel Sail) (067-rbac-troubleshooting)

  • PHP 8.4.x (Composer constraint: ^8.2) + Laravel 12, Filament 5, Livewire 4+, Pest 4, Sail 1.x (073-unified-managed-tenant-onboarding-wizard)

  • PostgreSQL (Sail) + SQLite in tests where applicable (073-unified-managed-tenant-onboarding-wizard)

  • PHP 8.4 (Laravel 12) + Filament v5, Livewire v4, Filament Infolists (schema-based) (078-operations-tenantless-canonical)

  • PostgreSQL (no new migrations — read-only model changes) (078-operations-tenantless-canonical)

  • PHP 8.4.15 (Laravel 12) + Filament v5, Livewire v4, Tailwind v4 (080-workspace-managed-tenant-admin)

  • PostgreSQL (via Sail) (080-workspace-managed-tenant-admin)

  • PHP 8.4.15 + Laravel 12, Filament v5, Livewire v4, Socialite v5 (081-provider-connection-cutover)

  • PHP 8.4.x + Laravel 12, Filament v5, Livewire v4 (082-action-surface-contract)

  • PHP 8.4 (Laravel 12) + Filament v5 (Livewire v4), Queue/Jobs (Laravel), Microsoft Graph via GraphClientInterface (084-verification-surfaces-unification)

  • PostgreSQL (JSONB-backed OperationRun.context) (084-verification-surfaces-unification)

  • PHP 8.4.15 (Laravel 12) + Filament v5, Livewire v4, Pest v4, Tailwind CSS v4, Laravel Sail (085-tenant-operate-hub)

  • PostgreSQL (primary) + session (workspace context + last-tenant memory) (085-tenant-operate-hub)

  • PHP 8.4 (Laravel 12) + Filament v5, Livewire v4, Laravel Sail, Tailwind CSS v4 (085-tenant-operate-hub)

  • PostgreSQL (Sail), SQLite in tests (087-legacy-runs-removal)

  • PHP 8.4.x + Laravel 12, Filament v5, Livewire v4, Microsoft Graph integration via GraphClientInterface (095-graph-contracts-registry-completeness)

  • PHP 8.4.15 (Laravel 12) + Filament v5, Livewire v4, Laravel Queue, Laravel Notifications (100-alert-target-test-actions)

  • PostgreSQL (Sail locally); SQLite is used in some tests (101-golden-master-baseline-governance-v1)

  • PHP 8.4 (Laravel 12) + Filament v5, Livewire v4, OperateHubShell support class (103-ia-scope-filter-semantics)

  • PostgreSQL — no schema changes (103-ia-scope-filter-semantics)

  • PHP 8.4 (Laravel 12) + Filament v5, Livewire v4, Pest v4 (104-provider-permission-posture)

  • PostgreSQL (via Sail), JSONB for stored report payloads and finding evidence (104-provider-permission-posture)

  • PHP 8.4 / Laravel 12 + Filament v5, Livewire v4, Tailwind CSS v4 (107-workspace-chooser)

  • PostgreSQL (existing tables: workspaces, workspace_memberships, users, audit_logs) (107-workspace-chooser)

  • PHP 8.4 (Laravel 12) + Filament v5, Livewire v4, Laravel Framework v12 (109-review-pack-export)

  • PostgreSQL (jsonb columns for summary/options), local filesystem (exports disk) for ZIP artifacts (109-review-pack-export)

  • PHP 8.4 + Laravel 12, Filament v5, Livewire v4 (116-baseline-drift-engine)

  • PHP 8.4, Laravel 12, Filament v5, Livewire v4 + Laravel framework, Filament admin panels, Livewire, PostgreSQL JSONB persistence, Laravel Sail (120-secret-redaction-integrity)

  • PostgreSQL (policy_versions, operation_runs, audit_logs, related evidence tables) (120-secret-redaction-integrity)

  • PHP 8.4.15 / Laravel 12 + Filament v5 + Livewire v4.0+ + Tailwind CSS v4 (121-workspace-switch-fix)

  • PostgreSQL + session-backed workspace context; no schema changes (121-workspace-switch-fix)

  • PHP 8.4.15 / Laravel 12 + Filament v5, Livewire v4.0+, Tailwind CSS v4, Pest v4 (122-empty-state-consistency)

  • PostgreSQL + existing workspace/tenant session context; no schema changes (122-empty-state-consistency)

  • PHP 8.4 runtime target on Laravel 12 code conventions; Composer constraint php:^8.2 + Laravel 12, Filament v5.2.1, Livewire v4, Pest v4, Laravel Sail (123-operations-auto-refresh)

  • PostgreSQL primary app database (123-operations-auto-refresh)

  • PHP 8.4.15 + Laravel 12, Filament 5, Livewire 4, Tailwind CSS 4, existing CoverageCapabilitiesResolver, InventoryPolicyTypeMeta, BadgeCatalog, and TagBadgeCatalog (124-inventory-coverage-table)

  • N/A for this feature; page remains read-only and uses registry/config-derived runtime data while PostgreSQL remains unchanged (124-inventory-coverage-table)

  • PHP 8.4.15 + Laravel 12, Filament 5, Livewire 4, Tailwind CSS 4, existing BadgeCatalog / BadgeRenderer, existing UI enforcement helpers, existing Filament resources, relation managers, widgets, and Livewire table components (125-table-ux-standardization)

  • PostgreSQL remains unchanged; this feature is presentation-layer and behavior-layer only (125-table-ux-standardization)

  • PHP 8.4.15 + Laravel 12, Filament v5, Livewire v4.0+, Tailwind CSS v4, Pest v4, existing BadgeCatalog / BadgeRenderer, existing TagBadgeCatalog / TagBadgeRenderer, existing Filament resource tables (126-filter-ux-standardization)

  • PostgreSQL remains unchanged; session persistence uses Filament-native session keys and existing workspace/tenant contex (126-filter-ux-standardization)

  • PHP 8.4 (Laravel 12) + Filament v5, Livewire v4, Laravel Sail, Microsoft Graph provider stack (127-rbac-inventory-backup)

  • PostgreSQL for tenant-owned inventory, backup items, versions, verification outcomes, and operation runs (127-rbac-inventory-backup)

  • PostgreSQL via Laravel Sail (128-rbac-baseline-compare)

  • PostgreSQL via Laravel Sail plus session-backed workspace and tenant contex (129-workspace-admin-home)

  • PostgreSQL via Laravel Sail using existing baseline_snapshots, baseline_snapshot_items, and JSONB presentation source fields (130-structured-snapshot-rendering)

  • PostgreSQL via Laravel Sail, plus existing session-backed workspace and tenant contex (131-cross-resource-navigation)

  • PostgreSQL via Laravel Sail plus existing workspace and tenant context, existing Eloquent relations, and provider-derived identifiers already stored in domain records (132-guid-context-resolver)

  • PostgreSQL via Laravel Sail; no schema change expected (133-detail-page-template)

  • PostgreSQL via Laravel Sail; existing audit_logs table expanded in place; JSON context payload remains application-shaped rather than raw archival payloads (134-audit-log-foundation)

  • PHP 8.4 on Laravel 12 + Filament v5, Livewire v4, Pest v4, Laravel Sail (135-canonical-tenant-context-resolution)

  • PostgreSQL application database (135-canonical-tenant-context-resolution)

  • PostgreSQL application database and session-backed Filament table state (136-admin-canonical-tenant)

  • PHP 8.4.15 + Laravel 12, Filament v5, Livewire v4, Laravel Sail, Pest v4, PHPUnit v12 (137-platform-provider-identity)

  • PostgreSQL via Laravel migrations and encrypted model casts (137-platform-provider-identity)

  • PHP 8.4 (Laravel 12) + Filament v5 (Livewire v4), Laravel Blade, existing onboarding/verification support classes (139-verify-access-permissions-assist)

  • PostgreSQL; existing JSON-backed onboarding draft state and OperationRun.context.verification_report (139-verify-access-permissions-assist)

  • PHP 8.4.15 + Laravel 12, Filament v5, Livewire v4, PostgreSQL, Laravel Sail, Pest v4, existing OperationRunService, ProviderOperationStartGate, onboarding services, workspace audit logging (140-onboarding-lifecycle-operation-checkpoints-concurrency-mvp)

  • PostgreSQL tables including managed_tenant_onboarding_sessions, operation_runs, tenants, and provider-connection-backed tenant records (140-onboarding-lifecycle-operation-checkpoints-concurrency-mvp)

  • PostgreSQL via Laravel Sail for existing source records and JSON payloads; no new persistence introduced (141-shared-diff-presentation-foundation)

  • PHP 8.4.15 / Laravel 12 + Filament v5, Livewire v4.0+, Tailwind CSS v4, shared App\Support\Diff foundation from Spec 141 (142-rbac-role-definition-diff-ux-upgrade)

  • PostgreSQL via Laravel Sail for existing findings.evidence_jsonb; no schema or persistence changes (142-rbac-role-definition-diff-ux-upgrade)

  • PHP 8.4.15 + Laravel 12, Filament v5, Livewire v4, Pest v4, Tailwind CSS v4 (143-tenant-lifecycle-operability-context-semantics)

  • PostgreSQL via Laravel Eloquent models and workspace/tenant scoped tables (143-tenant-lifecycle-operability-context-semantics)

  • PHP 8.4 (Laravel 12) + Filament v5, Livewire v4, Laravel Gates and Policies, OperateHubShell, OperationRunLinks (144-canonical-operation-viewer-context-decoupling)

  • PostgreSQL plus session-backed workspace and remembered tenant context (no schema changes) (144-canonical-operation-viewer-context-decoupling)

  • PHP 8.4.15 with Laravel 12, Filament v5, Livewire v4.0+ + Filament Actions/Tables/Infolists, Laravel Gates/Policies, UiEnforcement, WorkspaceUiEnforcement, ActionSurfaceDeclaration, BadgeCatalog, TenantOperabilityService, OnboardingLifecycleService (145-tenant-action-taxonomy-lifecycle-safe-visibility)

  • PostgreSQL for tenants, onboarding sessions, audit logs, operation runs, and workspace membership data (145-tenant-action-taxonomy-lifecycle-safe-visibility)

  • PostgreSQL (existing tenant and operation records only; no schema changes planned) (146-central-tenant-status-presentation)

  • PostgreSQL plus existing session-backed workspace and remembered-tenant context; no schema change planned (147-tenant-selector-remembered-context-enforcement)

  • PHP 8.4.15 + Laravel 12, Filament 5, Livewire 4, Pest 4, existing support-layer helpers such as UiEnforcement, CapabilityResolver, WorkspaceContext, OperateHubShell, TenantOperabilityService, and TenantActionPolicySurface (148-central-tenant-operability-policy)

  • PostgreSQL plus existing session-backed workspace and remembered-tenant context; no schema change planned for the first implementation slice (148-central-tenant-operability-policy)

  • PHP 8.4.15 + Laravel 12, Filament 5, Livewire 4, Pest 4, existing OperationRunService, TrackOperationRun, ProviderOperationStartGate, TenantOperabilityService, CapabilityResolver, and WriteGateInterface seams (149-queued-execution-reauthorization)

  • PostgreSQL-backed application data plus queue-serialized OperationRun context; no schema migration planned for the first implementation slice (149-queued-execution-reauthorization)

  • PHP 8.4.15 + Laravel 12, Filament v5, Livewire v4, PostgreSQL, Pest 4 (150-tenant-owned-query-canon-and-wrong-tenant-guards)

  • PostgreSQL with existing findings and audit_logs tables; no new storage engine or external log store (151-findings-workflow-backstop)

  • PHP 8.4.15 (feat/005-bulk-operations)

Project Structure

src/
tests/

Commands

Add commands for PHP 8.4.15

Code Style

PHP 8.4.15: Follow standard conventions

Recent Changes

  • 151-findings-workflow-backstop: Added PHP 8.4.15 + Laravel 12, Filament v5, Livewire v4, Laravel Sail, Pest v4, PHPUnit v12
  • 150-tenant-owned-query-canon-and-wrong-tenant-guards: Added PHP 8.4.15 + Laravel 12, Filament v5, Livewire v4, PostgreSQL, Pest 4
  • 149-queued-execution-reauthorization: Added PHP 8.4.15 + Laravel 12, Filament 5, Livewire 4, Pest 4, existing OperationRunService, TrackOperationRun, ProviderOperationStartGate, TenantOperabilityService, CapabilityResolver, and WriteGateInterface seams