Product direction

Build the boundary before expanding the surface.

Direction, not a release promise. ArtifactFlow's alpha is intentionally narrow while the next format focus brings searchable PDF artifacts and Word documents into the same versioned vault. Each format moves forward only after its authorization, storage, parsing, preview, and operational boundaries are written down and proven.

Available now

The alpha has shipped and remains deliberately focused.

The current alpha line is feature-frozen while it gathers feedback. Work stays concentrated on security, correctness, release readiness, documentation, and small usability improvements to behavior that already exists.

  • HTML, Markdown, and MermaidPreserve, search, version, and share artifacts through authenticated personal and shared workspaces.
  • Visible page hierarchyThe Library, Overview, page detail, and MCP expose authorization-filtered parent and child context within one workspace.
  • Isolated HTML executionGenerated HTML runs on the separate artifact origin under the documented iframe, CSP, and signed-preview boundary.
  • Scoped MCP accessNine operations cover workspace discovery, taxonomy, search, read, create, update, and revert without granting preview capabilities.
The alpha boundary stays flat

Workspaces remain independent permission boundaries. Page hierarchy is navigation over the existing page model, not a second permission system or nested workspace inheritance.

Post-alpha candidate

External sharing requires a new capability boundary.

Expiring and one-time links are candidates for deliberate post-alpha work. They are not current features. Before implementation, ArtifactFlow needs an architecture decision covering the share origin, version semantics, recipient verification, downloads, revocation, and uniform failure behavior.

Any accepted design must store only a hash of the random secret, reveal only the selected page or version, re-check state on every redemption, consume one-time links atomically, preserve HTML isolation, and prove that tokens and restricted metadata do not leak.

Beta candidates

Document artifacts are the active roadmap focus.

Searchable PDF artifacts

PDFs would join the same permission-aware catalog and version history as other pages while remaining non-executable. Search needs bounded parsing, OCR, private originals, safe reading, and proof that titles, snippets, files, and processing status never leak.

Track PDF issue #32 ↗

Searchable Word documents

Modern DOCX files would keep their private original, extracted searchable text, safe non-executable preview, and immutable replacements. ZIP limits, external relationships, embedded content, parser isolation, derivative cleanup, and optional generator-source pairing need explicit proof.

Track Word issue #33 ↗
Later candidate

Nested shared workspaces remain documented, but document artifacts are the current format focus. No candidate has a promised date or order.

Before beta

Scheduling follows proof, not the other way around.

  1. Write the product rule and architecture decision before changing schema or authorization behavior.
  2. Update the threat model and identify the information each new boundary could expose.
  3. Implement tests first, including authorization failures, concurrency, revocation, storage cleanup, and browser-level isolation.
  4. Pass the repository's static analysis, test, security, build, image, and release gates before presenting the work as available.

Explicitly not promised

A candidate is not a date, order, or commitment.

  • No target datesThe roadmap does not promise a release date or quarter for candidate work.
  • No guaranteed orderingFeedback and security findings may change priorities before a candidate is scheduled.
  • No built-in AI generationArtifactFlow preserves deliberate artifacts; it is not becoming an AI generation platform.
  • No broad public hosting productScoped external links are a candidate boundary, not a public marketplace or anonymous artifact-hosting service.
  • No automatic enterprise expansionSSO, a full approval system, and a broad enterprise RBAC suite remain outside the current roadmap.

Source of truth

Follow the repository when details change.

This page is a readable summary. The versioned repository roadmap remains authoritative and contains the detailed security properties and proof required for each candidate.