Teams App — Change Log¶
This log tracks software changes for this area.
Current status¶
| Item | Status | Notes |
|---|---|---|
| Active development | Open | Core + management flows implemented, audit logging active, policy-based permissions introduced |
| Next release target | TBA | Filtering, pagination, role semantics |
| Known risk | Medium | Role semantics + visibility consistency + policy adoption completeness |
Recent changes (newest first)¶
| Date | Type | Summary | Impact | Reference |
|---|---|---|---|---|
| 2026-04-14 | Refactor | Introduced policy-based authorization layer (org + team capabilities) | High | core.policies.* |
| 2026-04-14 | Test | Added full policy test coverage for org and team capabilities | High | tests/core/test_policies_*.py |
| 2026-04-14 | Refactor | Migrated service-layer permission checks to policy layer | High | teams.services.* |
| 2026-04-14 | Feature | Added audit logging for team entity mutations (create/update/deactivate/reactivate) | High | teams.services.team, core.audit |
| 2026-04-14 | Test | Added service-level and API-level audit assertions for team entity mutations | High | tests/teams/test_team_services.py, tests/teams/test_teams_api.py |
| 2026-04-14 | Feature | Added audit logging for team membership mutations (add, role change, primary switch, deactivate/reactivate) | High | teams.services.membership, core.audit |
| 2026-04-14 | Test | Added service-level and API-level audit assertions for membership mutations | High | tests/teams/test_membership_services.py, tests/teams/test_teams_api.py |
| 2026-04-14 | Feature | Expanded team roles (lead, deputy, member, specialist, trainee) | High | TeamMembership.Role |
| 2026-04-14 | Feature | Added team management endpoints (create/update/deactivate/reactivate) | High | Views / URLs |
| 2026-04-14 | Feature | Added membership management endpoints (add, role update, primary switch, deactivate/reactivate) | High | Views / URLs |
| 2026-04-14 | Refactor | Standardized team member payload via serializers | Medium | Serializers |
| 2026-04-14 | Test | Expanded service + API test coverage for management and permissions | High | Tests |
| 2026-04-14 | Feature | Implemented Teams app core (models, serializers, services, views, URLs) | High | Initial implementation |
Open items and status¶
| ID | Title | Status | Priority | Owner | Target | Reference |
|---|---|---|---|---|---|---|
| TEAMS-006 | Introduce pagination for membership endpoints | Open | P2 | Unassigned | TBA | |
| TEAMS-007 | Add filtering (team, role, active) to membership endpoints | Open | P2 | Unassigned | TBA | |
| TEAMS-009 | Add caching for heavy membership queries | Open | P3 | Unassigned | TBA | |
| TEAMS-011 | Define role hierarchy rules (lead vs deputy vs specialist) | Open | P1 | Unassigned | TBA | |
| TEAMS-012 | Add validation for inactive team mutations | Open | P2 | Unassigned | TBA | |
| TEAMS-013 | Include org-role context in team member responses | Open | P3 | Unassigned | TBA | |
| TEAMS-015 | Add audit visibility/query endpoints for operational review | Open | P3 | Unassigned | TBA | |
| TEAMS-016 | Complete migration of all permission checks to policy layer | Open | P1 | Unassigned | TBA |
Completed items¶
| ID | Title | Date | Notes |
|---|---|---|---|
| TEAMS-001 | Expand team roles beyond lead/member | 2026-04-14 | Implemented with 5-role system |
| TEAMS-002 | Add team management endpoints | 2026-04-14 | Full CRUD-lite (soft delete/reactivate) |
| TEAMS-003 | Add membership management endpoints | 2026-04-14 | Add/update/deactivate/reactivate |
| TEAMS-004 | Add role update endpoint | 2026-04-14 | Implemented |
| TEAMS-005 | Add primary team switching endpoint | 2026-04-14 | Implemented |
| TEAMS-008 | Replace inline member payload with serializer | 2026-04-14 | Implemented |
| TEAMS-010 | Add audit logging for membership changes | 2026-04-14 | Implemented in services + covered by service/API tests |
| TEAMS-014 | Add audit logging for team entity mutations | 2026-04-14 | Implemented in services + covered by service/API tests |
Known bugs¶
| ID | Symptom | Severity | Status | Workaround | Reference |
|---|---|---|---|---|---|
| BUG-TEAMS-001 | DB constraint error if multiple primary teams set manually | Medium | Open | Always use service layer | |
| BUG-TEAMS-002 | Missing team returns 200 instead of 404 | Low | Open | Treat as API contract | |
| BUG-TEAMS-003 | Team member payload lacks org role context | Low | Open | Use membership endpoint instead | |
| BUG-TEAMS-004 | Role semantics not yet enforced (e.g. deputy vs lead) | Medium | Open | No strict hierarchy validation yet |
Breaking changes and migrations¶
| Date | Change | Action required | Reference |
|---|---|---|---|
| 2026-04-14 | Added Teams app schema | Run migrations | Initial release |
| 2026-04-14 | Expanded TeamMembership.Role enum |
Ensure frontend/API supports new roles | Role expansion |
| 2026-04-14 | Introduced policy-based permission layer | Replace direct role checks with policy helpers | core.policies.* |
Notes¶
1. Policy-based authorization is now the foundation¶
The app has moved from:
- direct role checks (if role == ...)
to: - capability-based checks via policy layer
Examples:
- can_manage_teams
- can_view_team
- can_manage_team_memberships
This enables: - centralized permission logic - easier evolution of roles - safer multi-tenant behavior
2. Team role system is flexible but not enforced¶
Current roles:
- lead
- deputy
- member
- specialist
- trainee
Important: - Roles are semantic only - No strict hierarchy enforcement yet
Next: - define behavioral differences - introduce hierarchy rules
3. Visibility logic remains critical¶
Access depends on: - org-level capabilities - team membership
All checks should go through:
- core.policies.*
- service layer wrappers
Avoid: - role string checks in views - duplicated logic
4. Primary team is a system-wide invariant¶
Rules: - only one primary team per user - enforced via DB constraint + service logic
Used by: - planning - workforce defaults - reporting
High-risk area → must stay centralized
5. Teams app is now a core operational module¶
The app now handles: - team lifecycle - membership lifecycle - role assignment - primary team logic - full audit trail
This is no longer just a grouping model — it is operational infrastructure
6. Audit logging is fully integrated¶
Audit coverage:
Teams - create - update - deactivate - reactivate
Memberships - add/update - role change - primary assignment - deactivate/reactivate
Important: - audit originates in service layer - covered by tests
Missing: - audit query endpoints
7. Next logical step¶
- Define role hierarchy + permissions
- Add filtering + pagination
- Introduce role-based behavior
- Add audit retrieval endpoints
- Complete policy-layer adoption across all apps