Implementation Status Matrix
Detailed status of protocol implementations across ObjectStack packages
Implementation Status Matrix
This document provides a comprehensive overview of which protocols from @objectstack/spec have been implemented in the ObjectStack packages.
Last Updated: July 2026
This matrix is generated from actual codebase analysis and represents the current implementation status.
Status Legend
| Symbol | Status | Description |
|---|---|---|
| β | Fully Implemented | Production-ready implementation with all core features |
| β οΈ | Partially Implemented | Basic implementation, missing advanced features |
| π‘ | Partially Delivered | Shipping implementation; full protocol parity still in progress |
| π§ | In Progress | Currently being developed |
| π | Planned | Scheduled for future implementation |
| β | Not Implemented | Protocol defined but not yet implemented |
Core Infrastructure (Kernel)
Runtime & Kernel
| Protocol | @objectstack/core | @objectstack/runtime | @objectstack/objectql | Status |
|---|---|---|---|---|
| Manifest | β | β | β | β Full |
| Context | β | β | β | β Full |
| Plugin | β | β | β | β Full |
| Plugin Lifecycle | β | β | β | β Full |
| Plugin Capability | β | β | β | β Full |
| Service Registry | β | β | β | β Full |
| Startup Orchestrator | β | β | β | β Full |
| Events | β | β | β | β Full |
Notes:
- Core package provides complete microkernel implementation
- Plugin system supports the
init/start/destroylifecycle, dependency resolution, and service injection β theonInstall/onEnable-style hook family was retired in v17 as never-implemented (#4212) - Event bus enables inter-plugin communication;
IPluginLifecycleEventsregisters the 14 lifecycle events that actually fire, andLifecycleEventNamesoft-typeshook/trigger(#4241) - ObjectQL serves as the example kernel β a reference implementation that will be modularized into plugins
Data Infrastructure
| Protocol | @objectstack/objectql | @objectstack/runtime | @objectstack/driver-memory | Status |
|---|---|---|---|---|
| Driver | β | β | β οΈ | β Interface |
| Datasource | β | β | β | β Full |
| Data Engine | β | β | β | β Full |
| Query | β | β οΈ | β οΈ | β οΈ Partial |
| Filter | β | β οΈ | β οΈ | β οΈ Partial |
Notes:
- ObjectQL implements complete IDataEngine interface
- Memory driver is the reference implementation: filters, sorting, pagination, aggregations, snapshot transactions, streaming and
syncSchema()are on; joins, window functions, subqueries, full-text and vector search are off (InMemoryDriver.supports) - Advanced query features (joins, window functions, subqueries) require production drivers
- Memory driver supports aggregations (groupBy, count, sum, avg, min, max)
Metadata Framework
Runtime Boundary β runtime metadata is file/artifact-backed and read-only at boot. Database-backed metadata persistence exists for explicitly configured control-plane services, not as an automatic runtime project-DB bridge.
- Metadata API (list types, list items, get item) is fully functional
- Metadata is loaded from config files or
dist/objectstack.jsonat startup and held in memory MetadataPluginauto-provisions thesys_metadata/sys_metadata_historystorage objects (plus the ADR-0067 commit log and the metadata audit trail) by default, soPUT /api/v1/meta/{type}/{name}always has somewhere to write. Per-project (cloud) kernels opt out withregisterSystemObjects: false, because there the control plane owns those tablesMetadataPlugindoes not auto-bridge ObjectQL to aDatabaseLoaderβ there is no automatic runtime project-DB bridge, and nothing in the packages calls the bridge during boot. Database-backed metadata is an explicitMetadataManageropt-in (setDataEngine()/setDatabaseDriver(), or adatasource+driverpair on the manager config), and even then it is control-plane only: both methods return early whenever anenvironmentIdis supplied, so a per-project kernel never gets a database-backed metadata loader- The artifact source is
artifactSource: { mode: 'local-file', path }β a compiled artifact read from a filesystem path or fetched from anhttp(s)URL (the control plane's public/pub/v1/environments/:id/artifact[?commit=β¦]route serves exactly such URLs), honored by all three bootstrap modes (eager/lazy/artifact-only). A secondartifact-apimode (a Bearer-authenticated control-plane pull) this page once called "Future / reserved" was removed while resolving #4246: it had zero consumers in any repo β the cloud runtime uses its ownArtifactApiClient, and package installs into a running OSS instance go through@objectstack/cloud-connectionβ and a still-configuredartifact-apisource now fails loudly atstart()instead of lingering half-declared - Future: durable local artifact cache β remote artifact URLs re-fetch on every boot
System Services
| Protocol | Implementation Package | Status | Notes |
|---|---|---|---|
| Logging | @objectstack/core | β | Cross-platform logger (browser + server) |
| API Registry | @objectstack/core | β | Central endpoint registry |
| Metrics | @objectstack/observability | β | Metrics exporters shipped (metrics-exporters.ts) |
| Tracing | @objectstack/observability | β οΈ | Error/exporter pipeline shipped (error-exporters.ts); full distributed tracing in progress |
| Audit | @objectstack/plugin-audit | β | Audit writers + audit objects shipped |
| Job | @objectstack/service-job | β | Job service with cron/db/interval adapters |
| Cache | @objectstack/service-cache | β | ICacheService with in-memory and Redis adapters (cache-service-plugin.ts); HTTP caching ships separately in @objectstack/rest |
| Translation | @objectstack/service-i18n | β | i18n/translation service with file adapter |
| Feature Flags | β | π | Planned |
| Encryption | @objectstack/service-settings | β οΈ | ICryptoProvider seam with a local AES-256-GCM provider (local-crypto-provider.ts); secret fields are encrypted at rest into sys_secret (objectql/secret-fields.ts). Managed KMS/Vault providers not shipped |
| Compliance | β | π | Planned |
| Masking | β | π | Planned |
| Notification | @objectstack/service-messaging | π‘ | Framework pipeline shipped; objectui bell cut-over remains |
| Change Management | β | π | Planned |
| Collaboration | β | π | Planned |
Data Layer (ObjectQL)
Core Data Modeling
| Protocol | @objectstack/spec | @objectstack/objectql | @objectstack/client | Status |
|---|---|---|---|---|
| Field | β | β | β | β Full |
| Object | β | β | β | β Full |
| Validation | β | β οΈ | β | β οΈ Partial |
| Hook | β | β | β | β Full |
| Dataset | β | β | β | β
@objectstack/service-analytics |
| Mapping | β | β | β | β Not Impl |
| Document | β | β | β | β Not Impl |
| External Lookup | β | β | β | β Not Impl |
Field Type Support:
| Field Type | Implementation | Notes |
|---|---|---|
| text, textarea, email, url, phone | β | Full support |
| number, currency, percent | β | Full support |
| boolean, toggle | β | Full support (there is no checkbox type β a checkbox group is checkboxes) |
| date, datetime, time | β | Full support |
| select, multiselect | β | Full support |
| lookup, master_detail | β | Full support in spec, partial in memory driver |
| formula | β | CEL-backed formula fields are implemented |
| summary | β | Server-side rollups for count/sum/min/max/avg on child records |
| json, tags | β | Full support (there is no array type β use json, tags, or the repeater embedded type) |
| file, image | β | File-class fields (image/file/avatar/video/audio) hold an opaque sys_file id; ownership + release are tracked by @objectstack/service-storage |
Query Engine
| Protocol | @objectstack/objectql | @objectstack/client | @objectstack/driver-memory | Status |
|---|---|---|---|---|
| Query AST | β | β | β οΈ | β Full |
| Query Builder | β | β | β | β Client |
| Filter Operators | β | β | β οΈ | β οΈ Partial |
| Aggregations | β | β | β | β Full |
| Joins | β | β | β | β οΈ Driver-dependent |
| Sorting | β | β | β | β Full |
| Pagination | β | β | β | β Full |
| Window Functions | β | β | β | β Spec only |
| Subqueries | β | β | β | β Spec only |
Notes:
- Full query protocol is defined and implemented in ObjectQL engine
- Actual query capability depends on driver implementation
- Memory driver covers filters, sorting, pagination and aggregations; joins, window functions and subqueries are off
- Client SDK provides query builder utilities (
QueryBuilder/FilterBuilder,createQuery/createFilter)
API Layer (Transport)
HTTP & REST
| Protocol | @objectstack/rest | @objectstack/runtime | @objectstack/plugin-hono-server | @objectstack/client | Status |
|---|---|---|---|---|---|
| REST Server | β | β (re-export) | β | β | β Full |
| HTTP Server | β | β | β | β | β Full |
| Endpoint | β | β | β | β | β Full |
| Router | β | β | β | β | β Full |
| Discovery | β | β | β | β | β Full |
| Contract | β | β | β | β | β οΈ Partial |
| Protocol | β | β | β | β | β Full |
| Errors | β | β | β | β | β Full |
| HTTP Cache | β | β | β | β | β Full |
| Batch | β | β | β | β | β Full |
The data (/api/v1/data), metadata (/api/v1/meta), discovery (/api/v1/discovery), and batch endpoints are implemented in @objectstack/rest (rest-server.ts β registerDiscoveryEndpoints); @objectstack/runtime re-exports RestServer from that package and provides the underlying HTTP server/dispatcher.
REST Endpoints Implemented:
| Endpoint Pattern | Method | Purpose | Status |
|---|---|---|---|
/api/v1 | GET | API discovery (alias; the SDK connects via /api/v1/discovery) | β |
/api/v1/meta | GET | List metadata types | β |
/api/v1/meta/{type} | GET | List items of type | β |
/api/v1/meta/{type}/{name} | GET | Get specific metadata item | β |
/api/v1/data/{object} | GET | List records | β |
/api/v1/data/{object}/{id} | GET | Get single record | β |
/api/v1/data/{object} | POST | Create record | β |
/api/v1/data/{object}/{id} | PATCH | Update record | β |
/api/v1/data/{object}/{id} | DELETE | Delete record | β |
/api/v1/data/{object}/createMany | POST | Batch create | β |
/api/v1/data/{object}/updateMany | POST | Batch update | β |
/api/v1/data/{object}/deleteMany | POST | Batch delete | β |
/api/v1/data/{object}/{id}/clone | POST | Clone a record (gated by enable.clone) | β |
/api/v1/data/{object}/batch | POST | Atomic batch operations | β |
/api/v1/batch | POST | Cross-object atomic batch (parent + children in one transaction, $ref) | β |
Every route carries the /api/v1 prefix. When project scoping is enabled each row is additionally mirrored under /api/v1/environments/{environmentId}. The full audited route list lives in packages/rest/src/rest-route-ledger.ts.
Advanced Protocols
| Protocol | Implementation | Status | Notes |
|---|---|---|---|
| Analytics | β | β | ObjectQL aggregation plus @objectstack/service-analytics dataset execution; analytics read scope auto-bridges to security.getReadFilter for RLS-aware dashboards/reports |
| OData | β | π | Protocol defined, not implemented |
| Realtime | @objectstack/service-realtime | β οΈ | Realtime service shipped, but only the process-local 'memory' adapter (in-memory-realtime-adapter.ts); a Redis-backed HA adapter is a post-GA fast-follow |
| WebSocket | β | π | Protocol defined (spec/api/websocket.zod.ts); no WebSocket transport ships in any package β the realtime service is in-process pub/sub, not a socket transport |
UI Layer (ObjectUI)
View System
| Protocol | @objectstack/spec | Implementation | Status |
|---|---|---|---|
| View | β | π‘ | π‘ Studio/ObjectUI renders authored metadata surfaces; general-purpose renderer coverage is still incomplete |
| ListView | β | π‘ | π‘ ObjectUI grid/list surfaces support per-view persistence, filters, row actions, density, galleries, and permission-aware affordances; full protocol parity is ongoing |
| FormView | β | π‘ | π‘ ObjectUI forms support live field rules (visibleWhen / readonlyWhen / requiredWhen), inline-grid row rules, and server-aligned required enforcement |
| Page | β | π‘ | π‘ Record-page authoring, page create flows, block canvas editing, slotted record pages, and selected page blocks are implemented in ObjectUI; full component catalogue remains in progress |
| App | β | π‘ | π‘ Navigation metadata is consumed by the console/app shell; full renderer parity remains in progress |
| Dashboard | β | π‘ | π‘ ObjectUI renders metric/chart/list/pivot/funnel/table widgets, drill-downs (group β records β record chain), type-aware cells, and dataset-bound widgets; Studio can author per-widget dataset bindings (dataset / dimensions / values) |
| Report | β | π‘ | π‘ ObjectUI renders spec-native tabular/summary/matrix/joined reports, chart/KPI blocks, drill-downs, and dataset-bound reports |
| Action | β | π‘ | π‘ ObjectUI supports row/global/header actions, action modal transport, parameter collection, visibility CEL, and nested action runners |
| Component | β | π‘ | π‘ Selected page/record components render in ObjectUI (record:alert, related lists, highlights, page blocks); catalogue parity remains in progress |
| Theme | β | β | β Spec only |
| Widget | β | π‘ | π‘ Dashboard/report/list/form widgets render in ObjectUI; custom widget manifest/runtime parity remains in progress |
| Chart | β | π‘ | π‘ Recharts-backed dashboard/report charts cover bar/line/pie/area/scatter/funnel/gauge/treemap/sankey with formatting and field-coverage guards |
Notes:
- All UI protocols are fully defined in spec
- Metadata API can retrieve UI definitions (views, apps, pages, dashboards, reports, actions)
- Active Studio/ObjectUI source lives in the sibling
../objectuirepo and is bundled intopackages/consolevia the objectui refresh workflow - Metadata-admin curated forms now merge server-only fields back into the save payload, so a Studio form that exposes only part of a metadata type should not strip newer protocol properties
- The 2026-05-08 β 2026-06-08 ObjectUI scan covered 910 non-merge frontend commits. The largest functional clusters were metadata-admin/Studio, master-detail forms, reports/dashboards, record detail/related lists, action transport, flow designer, developer/API pages, AI draft publishing, and i18n.
- React SDK provides data hooks; the cross-surface renderer is still being completed in ObjectUI rather than in this backend repo
Automation Layer
Plugin-Provided Service β The kernel does NOT include an automation engine. Flow, workflow, and approval services are provided by plugins β the flow engine ships in @objectstack/service-automation, with approval nodes in @objectstack/plugin-approvals.
| Protocol | @objectstack/spec | Kernel | Plugin Required | Status |
|---|---|---|---|---|
| Flow | β | β | β | β
@objectstack/service-automation |
| Workflow | β | β | β | β
@objectstack/service-automation |
| Approval | β | β | β | β
@objectstack/plugin-approvals |
| Webhook | β | β | β | β
@objectstack/plugin-webhooks |
| ETL | β | β | β | π Plugin |
| Sync | β | β | β | π Plugin |
| Trigger Registry | β | β | β | β
trigger-api / trigger-record-change / trigger-schedule |
Notes:
- Hook system is implemented in ObjectQL (beforeFind, afterInsert, etc.) β this is data-layer eventing, not workflow automation
- The flow/workflow engine ships in
@objectstack/service-automation(engine.ts, builtin nodes,plugin.ts); approvals, webhooks, and triggers ship as@objectstack/plugin-approvals,@objectstack/plugin-webhooks,@objectstack/trigger-api,@objectstack/trigger-record-change, and@objectstack/trigger-schedule - ETL and Sync protocols are defined but not yet implemented as plugins
- Discovery API reports automation service as
unavailableuntil a plugin is registered
Security Layer
Plugin-Provided Service β The kernel does NOT handle authentication or authorization. Security services must be provided by plugins (e.g., @objectstack/plugin-auth). The Discovery API reports auth as unavailable until a plugin is registered.
Auth Service (plugin-auth)
CoreServiceName names a single auth service β there is no permission entry in that enum. Authentication/identity is what @objectstack/plugin-auth registers under that name. Authorization is registered outside CoreServiceName: @objectstack/plugin-security registers security (plus security.permissions, security.rls, security.fieldMasker) and @objectstack/plugin-sharing registers sharing, sharingRules, and shareLinks.
| Protocol | Area | @objectstack/spec | Kernel | Plugin Required | Status |
|---|---|---|---|---|---|
| Identity | Authentication | β | β | β | β
plugin-auth (better-auth) |
| Auth Config | Authentication | β | β | β | β
plugin-auth |
| Position | Authentication | β | β | β | β
plugin-auth + plugin-security |
| Organization | Authentication | β | β | β | β
plugin-auth (tenancy service) |
| Policy | Authentication | β | β | β | π Plugin |
| SCIM | Authentication | β | β | β | β οΈ plugin-auth, opt-in via OS_SCIM_ENABLED |
| Permission | Authorization | β | β Phase-1 | β | β
plugin-security |
| Sharing | Authorization | β | β | β | β
plugin-sharing |
| RLS | Authorization | β | β Phase-1 (tenant + owner) | β | β
plugin-security |
Notes:
- Security is delivered by three cooperating plugins, not one:
plugin-auth(identity,auth+tenancyservices),plugin-security(permissions, FLS, RLS, tenant wall), andplugin-sharing(OWD, sharing rules, per-record shares, share links) - Client SDK supports bearer token header β but token validation requires the auth plugin
- Auth route (
/auth/*) only appears in Discovery when the auth plugin is registered - Fine-grained authorization (RLS, sharing) lives in
plugin-security/plugin-sharing, not in the auth plugin. Territory-style access is expressed as an RLS dynamic-membership set (ExecutionContext.rlsMembership, e.g.id in current_user.territory_account_ids) rather than as a dedicated territory module - Phase-1 RBAC enforcement is live end-to-end: REST β ObjectQL β SecurityPlugin middleware now receives a populated
ExecutionContext(userId, tenantId, positions, permissions). Tenant isolation is enforced as a Layer 0 tenant wall (plugin-security/tenant-layer.ts, ADR-0095 D1) that AND-composesorganization_id == current_user.organization_idahead of and independently of business RLS β the earlier wildcardtenant_isolationRLS policy onmember_defaultwas retired (an OR-merged business policy could widen it). The defaultmember_defaultset still ships per-object overridessys_organization_self(id == current_user.organization_id) andsys_user_self(id == current_user.id) for the global tables that lack anorganization_idcolumn. The earliertenantFieldindirection (RLS expressions written against an abstracttenant_idcolumn then rewritten to the configured physical column at compile time) was removed β the placeholder, the column name, andRLSUserContext.organization_idare now the same name end-to-end. The legacyobjectql.registerTenantMiddleware(hardcodedwhere.tenant_idinjection that pre-dated SecurityPlugin) has been removed; SecurityPlugin is the sole authority for tenant isolation. Analytics now uses the same reusable read scope viasecurity.getReadFilter, so dataset-bound dashboards/reports do not bypass RLS. Verified cross-organization isolation onpnpm dev:crmacrosssys_organization,sys_member,sys_user,sys_user_permission_set,sys_position_permission_set. Anonymous traffic is always denied (ADR-0056 D2). The deployment-wide opt-out is gone:api.requireAuthwas retired in@objectstack/spec17 (#3963) and is now a tombstoned key that fails validation rather than reopening the data plane. The single decision lives in@objectstack/core(security/anonymous-deny.ts, 401UNAUTHENTICATED), and every surface that legitimately serves a session-less caller derives its own narrow authorization from a declaration instead: control-plane paths via the auth-gate allowlist, public forms viapublicFormGrant(ADR-0056 Option A), share links via a capability token validated then read as SYSTEM,book.audience: 'public'reads via the audience gate, and MCP via an OAuth token or API key. - OWD / sharing-model enforcement is live and proven end-to-end (ADR-0056):
private,public_read,public_read_write, andcontrolled_by_parentare enforced throughplugin-sharing+plugin-securityand verified by dogfood proofs over the real HTTP stack.object.sharingModelaccepts the canonical OWD vocabulary only (private/public_read/public_read_write/controlled_by_parent) β the legacyread/read_write/fullaliases were removed from the enum (ADR-0090 D4), and an unsetsharingModelon a custom object resolves toprivate(ADR-0090 D1). RLS owner policies resolvecurrent_user.emailin addition toid/organization_id/positions(#2054). Permission sets may declareisDefault: trueas the install-time suggestion to bind the set to the built-ineveryoneposition (ADR-0090 D5, superseding the ADR-0056 D7 fallback-profile mechanism). A sharing rule must state its criteria (#3896): all three write paths reject a match-all shape, a stored criteria-less rule matches nothing, and its materialised grants are revoked on the next reconcile.
AI Layer
The in-UI AI runtime below ships in ObjectOS, not in the
open-source framework. The agent / skill / tool schemas stay open in
@objectstack/spec/ai; the open-source framework exposes AI via
@objectstack/mcp (BYO-AI). The Implementation / Status columns
describe that separate runtime.
| Protocol | @objectstack/spec | Implementation | Status |
|---|---|---|---|
| Agent | β | ObjectOS runtime | β Agent runtime |
| Model Registry | β | ObjectOS runtime | β Model registry |
| RAG Pipeline | β οΈ | @objectstack/service-knowledge | β οΈ Knowledge service + knowledge-memory / knowledge-ragflow / embedder-openai plugins; spec defines the retrieval binding (ai/knowledge-source.zod.ts, ai/knowledge-document.zod.ts), not a pipeline DSL |
| NLQ | β | ObjectOS runtime | β οΈ Data-query tools |
| Conversation | β | ObjectOS runtime | β In-memory + ObjectQL conversation services |
| Agent Action | β | ObjectOS runtime | β οΈ Action/data/knowledge tools (tool.zod.ts + action_<name> tools) |
| Cost | β | β | β Spec only β usage.zod.ts accounts tokens/per-call cost; no budget enforcement |
| Predictive | β | β | β Not defined |
| Orchestration | β | ObjectOS runtime | β οΈ Agent tool orchestration |
| Feedback Loop | β | ObjectOS runtime | β οΈ Eval harness |
| DevOps Agent | β | β | β Not defined |
Notes:
- The
@objectstack/spec/aisurface is deliberately narrow β Agent, Skill, Tool, Conversation, Model Registry, Embedding, Usage, MCP, plus the knowledge-source / knowledge-document and solution-blueprint schemas. Application-level protocols (DevOps agents, predictive pipelines, AIOps, orchestration plans, NLQ services, RAG-pipeline DSLs, budget enforcement) were removed in v1 and have no schema today β see the scope note inpackages/spec/src/ai/index.ts - The ObjectOS runtime ships agents, model registry, conversation, tools, skills, and an eval harness
- RAG/embedding is provided by
@objectstack/service-knowledgeplus theknowledge-memory,knowledge-ragflow, andembedder-openaiplugins (all open) - Token/cost accounting has a schema (
ai/usage.zod.ts) but no shipping enforcement; the predictive and DevOps-agent protocols are not defined in spec at all
Integration Layer
| Protocol | @objectstack/spec | Implementation | Status |
|---|---|---|---|
| Connector | β | connector-rest, connector-openapi, connector-mcp, connector-slack | β REST/OpenAPI/MCP/Slack connectors shipped |
| SaaS Connector | β | connector-slack | β οΈ Slack connector shipped; broader SaaS catalogue in progress |
| Database Connector | β | @objectstack/driver-sql, driver-mongodb | β Delivered via the database drivers |
| File Storage | β | @objectstack/service-storage | β File storage service with local + S3 adapters and storage routes |
| Message Queue | β | @objectstack/service-queue | β οΈ Queue service shipped |
| GitHub Connector | β | β | β Spec only |
| Vercel Connector | β | β | β Spec only |
QA & Testing
| Protocol | @objectstack/spec | @objectstack/core | @objectstack/verify | Status |
|---|---|---|---|---|
| Testing | β | β | β | β Full |
Features Implemented:
- TestSuite, TestScenario, TestStep schemas β
- HTTP adapter for testing β
(
packages/core/src/qa/http-adapter.ts) - QA runner in core β
(
packages/core/src/qa/runner.ts) - Conformance/dogfood harnesses in
@objectstack/verifyandpackages/qa(dogfood,downstream-contract,http-conformance) β
There is no MSW package in this repo β browser API mocking is a devDependency of the sibling objectui frontend, and @objectstack/driver-memory is what backs those in-browser fixtures.
Implementation Roadmap
Phase 1: Core Infrastructure β COMPLETE
- Microkernel & Plugin System
- Logging System
- Service Registry
- Event Bus
- API Registry
Phase 2: Data Layer β COMPLETE
- ObjectQL Engine
- Schema Registry
- Protocol Implementation
- Basic Query Support
- CRUD Operations
- Hook System
Phase 3: API Layer β COMPLETE
- REST Server
- HTTP Server (Hono)
- Endpoint Generation
- Discovery API
- Metadata API
- Batch Operations
- HTTP Caching
Phase 4: Client SDKs β COMPLETE
- TypeScript Client
- React Hooks
- Query Builder
- Error Handling
Phase 5: Developer Tools β COMPLETE
- CLI Tools
- Config Validation
- Development Server
- Metadata Management
Phase 6: Advanced Features π§ IN PROGRESS
- Production Database Drivers β
@objectstack/driver-sql(PostgreSQL/MySQL dialects),@objectstack/driver-mongodb, and@objectstack/driver-sqlite-wasmship; additional dialect coverage ongoing - OData Support
- Realtime Subscriptions
- WebSocket Support
Phase 7: UI Layer π‘ IN PROGRESS
- UI Renderer
- Studio metadata-admin engine β generic metadata list/detail/edit surfaces, live preview, draft/publish/rollback, create-mode forms, server-side diagnostics, package scoping, and skew-safe curated inspectors
- Form conditional rules β ObjectUI supports
visibleWhen,readonlyWhen,requiredWhen, row-scoped inline-grid rules, and required-on-submit enforcement - Master-detail forms β inline subforms, spreadsheet-style line items, atomic batch create/edit, lookup auto-fill, line ordering, duplicate/reorder, and subtotal/tax/total stack
- Record detail + related lists β derived related lists, record-page assignment, action slots, system/audit sections, and opt-in reference rail
- Dashboard renderer/editor β widget layout persistence, drill-downs, pivot/funnel/table/list widgets, type-aware cells, and per-widget dataset binding authoring (
dataset,dimensions,values) - Report renderer/editor β spec-native summary/matrix/joined reports, chart/KPI blocks, drill-downs, dataset-bound reports, and i18n labels
- Flow/page designers β typed flow node config panels, simulator/debug runner, page block canvas, slotted record pages, and schema-driven block inspectors
- Action transport β row/global/header actions, modal parameter collection, visible CEL, popup-safe open actions, and nested action runner sharing
- Developer/admin console surfaces β Integrations & APIs, public forms, flow runs, approvals inbox, settings, marketplace/package management, AI draft review/publish
- List View Renderer full protocol parity
- Cross-surface UI Renderer full protocol parity
- Theme Engine
Phase 8: Automation (Plugin) π‘ IN PROGRESS
- Flow Engine Plugin
- Approval Node Plugin
- Trigger Registry Plugins β
@objectstack/trigger-api,@objectstack/trigger-record-change,@objectstack/trigger-schedule(including the time-relative trigger) - ETL Pipeline Plugin
- Sync Plugin
Phase 9: Security (Plugin) π‘ PHASE-1 LANDED
- Authentication Plugin (
@objectstack/plugin-auth, better-auth) - Authorization Plugin β
@objectstack/plugin-securityenforces CRUD/FLS/RLS in the ObjectQL middleware chain; REST β ObjectQL now propagatesExecutionContextend-to-end (Phase-1) - Row-Level Security β tenant isolation is a Layer 0 tenant wall (
plugin-security/tenant-layer.ts, ADR-0095 D1) that AND-composesorganization_id == current_user.organization_idindependently of business RLS (the earlier wildcardtenant_isolationpolicy onmember_defaultwas retired);member_defaultstill applies per-object overridessys_organization_self/sys_user_self. The earliertenantFieldrewrite indirection was removed: RLS column, placeholder, andRLSUserContext.organization_iduse the same canonical name end-to-end. Policyenabled: falseis enforced at the compiler choke point β a disabled policy no longer contributes its OR-branch grant (#3980) β and the voidrowLevelSecurity[].prioritykey was removed in@objectstack/spec17.0.0 (#3896 security audit) - Analytics RLS bridge β
@objectstack/service-analyticsauto-bridges tosecurity.getReadFilter(object, context)and fails closed when read-scope resolution cannot be safely applied - Multi-tenancy β verified cross-organization isolation on
pnpm dev:crm(Alice@OrgAlpha vs. Bob@OrgBeta only see their own records acrosssys_organization,sys_member,sys_user, andsys_*_permission_setlink tables) - Legacy
objectql.registerTenantMiddlewareremoved β SecurityPlugin is now the sole tenant-isolation authority - Organization-Wide Defaults / sharing model β
private,public_read,public_read_write, andcontrolled_by_parentenforced viaplugin-sharing+plugin-security, proven by dogfood over the real HTTP stack (ADR-0056). Canonical vocabulary only β legacy aliases removed from the enum (ADR-0090 D4); unset custom-object OWD resolves toprivate(ADR-0090 D1) - Sharing Rule evaluator β criteria rules re-evaluated on
afterInsert/afterUpdate(plugin-sharing/rule-hooks.ts); every authorable recipient maps 1:1 onto an enforcedexpandRecipientbranch (plugin-sharing/sharing-rule-service.ts) βuser,team,position,business_unit, andunit_and_subordinates(business-unit-subtree widening, ADR-0057 D5 / ADR-0090 D3). Under ADR-0078 enforce-or-remove,criteriais now the only rule type (owner-type rules were removed from the authoring surface because the static materialiser cannot track live membership), thegrouprecipient was renamed toteam,guestwas removed, andqueuestays reserved in the runtime contract but deliberately non-authorable - Everyone-baseline suggestion β a permission set may set
isDefault: trueas the install-time suggestion to bind it to the built-ineveryoneposition; resolved per-request as an additive baseline, no fallback cliff (ADR-0090 D5) - Default-deny for anonymous traffic β the global default-deny landed (ADR-0056 D2) and the
api.requireAuthopt-out was then removed in@objectstack/spec17 (#3963): the key is tombstoned and rejected at parse time, the deny decision is centralised in@objectstack/coresecurity/anonymous-deny.ts, and public forms self-authorize viapublicFormGrant(Option A) - Studio RLS visual editor
- Per-userΓorg permission cache
- Audit UI / denied-access logging
Phase 10: AI Integration π‘ IN PROGRESS
- RAG Pipeline β
@objectstack/service-knowledgeplus theknowledge-memory,knowledge-ragflow, andembedder-openaiplugins ship in this repo - MCP surface β
@objectstack/mcpexposes the platform to any BYO-AI client - Agent Framework (ObjectOS runtime; not in the open-source framework)
- NLQ Engine (ObjectOS runtime)
- Model Registry (ObjectOS runtime)
Summary Statistics
Overall Implementation Status
| Category | Total Protocols | Status |
|---|---|---|
| Data | 16 | Core modeling, hooks, and query engine fully implemented; document/mapping/external-lookup still pending |
| UI | 10 | Studio/ObjectUI render most authored surfaces (π‘); full cross-surface renderer parity in progress |
| API | 14 | REST/HTTP/discovery/batch fully implemented; OData and the WebSocket transport pending; GraphQL removed from the plan |
| System | 39 | Logging, audit, job, translation, metrics, cache, notification implemented; encryption partial (local crypto provider); several governance services pending |
| Auth (plugin) | 10 | Identity/organizations live (plugin-auth), permission + RLS live (plugin-security), OWD + sharing rules live (plugin-sharing); SCIM is opt-in |
| Automation (plugin) | 7 | Flow, workflow, approval, webhook, and triggers implemented; ETL/Sync pending |
| AI | 12 | Agents, model registry, conversation, tools, RAG implemented (ObjectOS runtime + open knowledge plugins); cost accounting has a schema but no enforcement, and the predictive / DevOps-agent protocols are not defined in spec |
| Integration | 7 | REST/OpenAPI/MCP/Slack connectors, file storage, and queue implemented; GitHub/Vercel connectors pending |
| QA | 1 | Fully implemented |
Implementation Coverage
Implementation spans every layer of the platform. Core infrastructure, data modeling, the REST API, client SDKs, security (Phase-1), automation, AI, and integration all have shipping implementations. Remaining gaps are concentrated in specific protocols (OData, cross-surface UI renderer parity, ETL/Sync, the mapping/document/external-lookup data protocols, and a handful of governance and AI-cost services) rather than entire layers. Refer to the per-layer tables above for protocol-level status.
Core Functionality Status
| Feature Area | Status | Production Ready |
|---|---|---|
| Kernel & Plugins | β | Yes |
| Data Modeling | β | Yes |
| Query Engine | β οΈ | Partial (depends on driver) |
| REST API | β | Yes |
| Client SDKs | β | Yes |
| Metadata System | β οΈ | Partial (sys_metadata persistence via MetadataPlugin; without it the kernel's in-memory fallback fills the slot and discovery reports it degraded) |
| HTTP Caching | β | Yes |
| Testing Tools | β | Yes |
| UI Rendering | π‘ | Partial (Studio/ObjectUI render authored surfaces; cross-surface renderer parity in progress) |
| Workflows | β | Yes (plugin: service-automation) |
| Security | β οΈ | Partial (Phase-1 RBAC/FLS/RLS via plugin-security; OWD + sharing rules via plugin-sharing; identity via plugin-auth) |
| AI Features | β οΈ | Partial (ObjectOS runtime + open knowledge plugins) |
Package Feature Matrix
| Feature | spec | core | objectql | runtime | client | client-react | cli | metadata | hono | memory |
|---|---|---|---|---|---|---|---|---|---|---|
| Protocol Definitions | β | β | β | β | β | β | β | β | β | β |
| Microkernel | β | β | β | β | β | β | β | β | β | β |
| Plugin System | β | β | β | β | β | β | β | β | β | β |
| Service Registry | β | β | β | β | β | β | β | β | β | β |
| Event Bus | β | β | β | β | β | β | β | β | β | β |
| Logging | β | β | β | β | β | β | β | β | β | β |
| Schema Registry | β | β | β | β | β | β | β | β | β | β |
| ObjectQL Engine | β | β | β | β | β | β | β | β | β | β |
| Protocol Implementation | β | β | β | β | β | β | β | β | β | β |
| REST Server | β | β | β | β | β | β | β | β | β | β |
| Endpoint Generation | β | β | β | β | β | β | β | β | β | β |
| HTTP Server | β | β | β | β | β | β | β | β | β | β |
| Client SDK | β | β | β | β | β | β | β | β | β | β |
| Query Builder | β | β | β | β | β | β | β | β | β | β |
| React Hooks | β | β | β | β | β | β | β | β | β | β |
| CLI Commands | β | β | β | β | β | β | β | β | β | β |
| Config Validation | β | β | β | β | β | β | β | β | β | β |
| Metadata Loading | β | β | β | β | β | β | β | β | β | β |
| File Watching | β | β | β | β | β | β | β | β | β | β |
| Database Driver | β | β | β | β | β | β | β | β | β | β οΈ |
The REST server, endpoint generation, and data/meta/batch endpoints are implemented in the
@objectstack/restpackage (not shown as a column above);@objectstack/runtimere-exportsRestServerfrom it.