Open decisions
Already closed
Section titled “Already closed”- NATS JetStream is the V1 internal raw-ingestion broker.
- Netmore topic, payload, QoS, exclusion, malformed storage, and SHA-256 idempotency semantics are documented and implemented.
- V1 interactive authentication uses local username/password login with Argon2id, short-lived identity-only access JWTs, opaque rotating refresh tokens, explicit organization descendant grants, and seven-year audit retention.
- Authentication architecture remains compatible with future tenant-specific OIDC without treating token claims as authoritative permission state.
- Measurement keys are constrained by the released Device Type field catalog; unknown output is rejected before persistence.
- The initial metrics, log aggregation, dashboard, alerting, public-status, and SLO-reporting stack is implemented. Live target-cluster evidence remains an operational gate rather than an architecture decision.
- Studio, Scripts, Templates, and Actions are capability areas of one Flow product. They do not define separate automation systems.
Still open
Section titled “Still open”- Service accounts, personal access tokens, MFA, and OIDC provider mapping.
- Whether a later device can have multiple simultaneous organization assignments; V1 allows exactly one and preserves append-only history.
- Which production retention, compression, and aggregation features can remain on the TimescaleDB Apache-2 edition and which would require a separately approved license choice.
- Export storage, retention, CSV columns, maximum range, download expiry, and compression.
- Scheduled execution and alerting for authentication and audit maintenance.
- Independent encrypted backup targets, bootstrap credentials, WAL strategy, retention, alerting, RPO/RTO, and isolated restore cadence for OpenBao and TimescaleDB.
- The date and operating model for OAuth-based Microsoft 365 delivery before password-based SMTP AUTH is removed.
No implementation may silently choose one of these outcomes. Close the decision in an ADR, contract, architecture document, and roadmap update before adding the dependent code or deployment configuration.