Available now
The alpha has shipped and remains deliberately focused.
The current alpha line is feature-frozen while it gathers feedback. Work stays concentrated on security, correctness, release readiness, documentation, and small usability improvements to behavior that already exists.
- HTML, Markdown, and MermaidPreserve, search, version, and share artifacts through authenticated personal and shared workspaces.
- Visible page hierarchyThe Library, Overview, page detail, and MCP expose authorization-filtered parent and child context within one workspace.
- Isolated HTML executionGenerated HTML runs on the separate artifact origin under the documented iframe, CSP, and signed-preview boundary.
- Scoped MCP accessNine operations cover workspace discovery, taxonomy, search, read, create, update, and revert without granting preview capabilities.
Workspaces remain independent permission boundaries. Page hierarchy is navigation over the existing page model, not a second permission system or nested workspace inheritance.
Beta candidates
Document artifacts are the active roadmap focus.
Searchable PDF artifacts
PDFs would join the same permission-aware catalog and version history as other pages while remaining non-executable. Search needs bounded parsing, OCR, private originals, safe reading, and proof that titles, snippets, files, and processing status never leak.
Track PDF issue #32 ↗Searchable Word documents
Modern DOCX files would keep their private original, extracted searchable text, safe non-executable preview, and immutable replacements. ZIP limits, external relationships, embedded content, parser isolation, derivative cleanup, and optional generator-source pairing need explicit proof.
Track Word issue #33 ↗Nested shared workspaces remain documented, but document artifacts are the current format focus. No candidate has a promised date or order.
Before beta
Scheduling follows proof, not the other way around.
- Write the product rule and architecture decision before changing schema or authorization behavior.
- Update the threat model and identify the information each new boundary could expose.
- Implement tests first, including authorization failures, concurrency, revocation, storage cleanup, and browser-level isolation.
- Pass the repository's static analysis, test, security, build, image, and release gates before presenting the work as available.
Explicitly not promised
A candidate is not a date, order, or commitment.
- No target datesThe roadmap does not promise a release date or quarter for candidate work.
- No guaranteed orderingFeedback and security findings may change priorities before a candidate is scheduled.
- No built-in AI generationArtifactFlow preserves deliberate artifacts; it is not becoming an AI generation platform.
- No broad public hosting productScoped external links are a candidate boundary, not a public marketplace or anonymous artifact-hosting service.
- No automatic enterprise expansionSSO, a full approval system, and a broad enterprise RBAC suite remain outside the current roadmap.
Source of truth
Follow the repository when details change.
This page is a readable summary. The versioned repository roadmap remains authoritative and contains the detailed security properties and proof required for each candidate.