# Documentation Sitemap > **Status:** Current navigation index. Quarantined and authority-gated material is summarized without being presented as current guidance. ## Start here - [Documentation atlas](README.md) — placement, source-of-truth, linking, and migration rules. - [User guide](USER-GUIDE/README.md) — end-user workflows and product behavior. - [Administrator guide](ADMIN-GUIDE/README.md) — installation, configuration, operations, security, and recovery. - [Developer guide](DEVELOPER-GUIDE/README.md) — architecture, testing, integrations, and contributor material. - [API documentation](API/README.md) — API contract migration status. - [Reports index](reports/README.md) — review, audit, QA, security, and retained evidence. - [Archive index](archive/README.md) — superseded historical pages. ## Product and delivery control - [Product requirements](PRD.md) — normative requirements; currently marked draft and retaining authority-gated legacy references. - [Active task rollup](TASKS.md) — orchestrator-owned work state; workers do not modify it. - [MVP mission manifest](MISSION-MANIFEST.md) — control-plane mission rollup; activity and status remain under its authorized owner. - [Documentation catalog and truth audit](reports/documentation/2026-08-10-docs-catalog-audit.md) — complete baseline inventory, evidence labels, broken-link clusters, and migration recommendations. ## Protected current authority and executable books These paths remain canonical because current source/tests consume them or because the KBN authority process protects them. Relocation requires an explicitly coordinated authority and consumer migration, not documentation-only cleanup. - [Fleet configuration management](fleet/README.md) — executable roster-v2 operator book, schema, examples, and north-star projections. - [Fleet local canary](guides/fleet-local-canary.md) — protected Fleet validation procedure referenced by the current developer hold-site guide. - [Native Kanban/SOT index](native-kanban-sot/INDEX.md) — active canonical KBN contract and workstream index. - [Native Kanban/SOT requirements](requirements/native-kanban-sot.md) — active ratified requirements surface. - [KBN-101 database role split](native-kanban-sot/KBN-101-DB-ROLE-SPLIT.md) — active held database authority contract. - [Developer hold-site guide](guides/dev-guide.md) — protected current KBN-101 development boundary. - [Deployment hold-site guide](guides/deployment.md) — protected, non-operative PostgreSQL/deployment boundary. - [Tier-migration hold-site guide](guides/migrate-tier.md) — protected secure migration route and hold boundary. - [Federation setup hold site](federation/SETUP.md) — protected KBN-101 setup boundary; follow its explicit holds. ## User documentation - [Quickstart](USER-GUIDE/getting-started/quickstart.md) — installed-CLI first-use route with local PGlite safety boundaries. - [Web dashboard](USER-GUIDE/product/web-dashboard.md) — current routes, views, chat persistence, settings, and admin behavior. - [Discord conversations](USER-GUIDE/workflows/discord-conversations.md) — current authorized parent-channel, thread, attachment, and control workflow. ## Administrator documentation - [Administrator operations](ADMIN-GUIDE/operations/README.md) — current local procedures and explicitly held outlines. - [Upgrade safety and recovery](ADMIN-GUIDE/operations/upgrade-safety-and-recovery.md) — installed-CLI/local-PGlite upgrade and framework recovery. - [Mos connector lease operations](ADMIN-GUIDE/operations/mos-connector-lease-operations.md) — held/non-operative M1 outline while policy remains deny-all. - [Administrator security](ADMIN-GUIDE/security/README.md) — current security chapter index. - [SSO providers](ADMIN-GUIDE/security/sso-providers.md) — Authentik, WorkOS, and Keycloak configuration and discovery. - [Discord ingress security](ADMIN-GUIDE/security/discord-ingress.md) — service authentication, allowlists, bindings, roles, replay, and failure controls. ## Developer documentation - [Architecture index](DEVELOPER-GUIDE/architecture/README.md) — current architecture contracts, decisions, and draft RFCs. - [Channel protocol](DEVELOPER-GUIDE/architecture/channel-protocol.md) — shared DTOs and current Discord compatibility boundary; future adapters are draft. - [Lease-broker protocol](DEVELOPER-GUIDE/architecture/lease-broker-protocol.md) — authenticated Unix-socket protocol and persistence boundary. - [Lease-broker security](DEVELOPER-GUIDE/architecture/lease-broker-security.md) — identity, ancestry, filesystem, observer, and residual boundaries. - [Whole mutator-class gate](DEVELOPER-GUIDE/architecture/mutator-class-gate.md) — default-deny tool authorization and launch choke point. - [Compaction revocation](DEVELOPER-GUIDE/architecture/compaction-revocation.md) — lifecycle observers, generation fencing, and residual stale window. - [Architecture decisions](DEVELOPER-GUIDE/architecture/decisions/README.md) — implemented and accepted boundaries. - [Mos runtime portability M1](DEVELOPER-GUIDE/architecture/decisions/mos-runtime-portability-m1.md) — logical identity, connector lease, grants, audit, and fencing. - [Architecture RFCs](DEVELOPER-GUIDE/architecture/rfcs/README.md) — draft proposals without operational authority. - [Optional AI egress gateways](DEVELOPER-GUIDE/architecture/rfcs/optional-ai-egress-gateways.md) — draft proposal; LiteLLM and Bifrost are not integrated. - [Lease-broker operations and verification](DEVELOPER-GUIDE/testing/lease-broker-operations.md) — safe static/test workflow; live procedures remain held. - [Channel adapter authoring](DEVELOPER-GUIDE/integrations/channel-adapters.md) — current shared contract and Discord reference boundary. ## API transition - [API index](API/README.md) — consolidated gateway contract remains planned. - [Legacy Tess-scoped OpenAPI contract](openapi-tess.yaml) — valid OpenAPI 3.1 artifact with incomplete gateway coverage; canonical scope requires maintainer approval. ## Evidence and planning - [Reports index](reports/README.md) — all tracked report categories and evidence boundaries. - [Archived missions](archive/missions/README.md) — historical CLI, harness, install UX, and storage-abstraction delivery records. - [Archived planning](archive/planning/README.md) — historical briefs, board reviews, and work-package specifications. - [Archived work records](archive/work-records/README.md) — historical task scratchpads without live consumers. - [P8-003 performance report](reports/qa/p8-003-performance-optimization.md) — historical implementation evidence, not a current SLO. - [Plans index](plans/README.md) — approved intent and implementation/audit plans. - [Documentation information-architecture design](plans/2026-08-10-docs-information-architecture-design.md) — approved documentation structure decision. - [Documentation catalog-audit plan](plans/2026-08-10-docs-catalog-audit.md) — evidence method and migration acceptance criteria. - [Scratchpads index](scratchpads/README.md) — working memory and verification records. - [Documentation migration scratchpad](scratchpads/DOCS-IA-002-catalog-audit.md) — coordinator progress, verification, and resumability record. ## Authority-gated migration backlog The complete file-level backlog remains in the [documentation catalog](reports/documentation/2026-08-10-docs-catalog-audit.md). The groups below are intentionally not linked as current pages: - **Fleet configuration:** the executable book is restored at `docs/fleet/`; any future audience-book relocation requires coordinated source/test and authority migration. - **Federation:** the protected KBN-101 setup hold site remains canonical; disposition of the rest of the workstream requires maintainer/orchestrator confirmation. - **Native Kanban/KBN-101:** active SSOT, requirements, and hold-site documents remain canonical; task state and future placement require product-owner, Task-18, and orchestrator decisions. - **Tess:** mixed user, administrator, developer, migration, qualification, and API material requires audience splitting and a decision on active versus historical status. - **Gateway API:** the Tess-scoped OpenAPI artifact must not be renamed into the canonical full-gateway contract until scope, authentication, errors, schemas, and transport coverage are approved. - **Deployment and tier migration:** PostgreSQL, federated, bare-metal, Compose, Gateway/Web activation, and migration-runner procedures remain held under the repository safety policy. - **Mixed legacy guides and scratchpads:** remaining records are coupled to control documents, tests/fixtures, mission evidence, or held procedures; migrate them with their owners. - **Compaction-refresh probes:** scripts are Mos-gated and path-coupled; do not move or execute them as documentation cleanup. `docs/_old_structure/` remains read-only migration quarantine. It is not current navigation and must not be used as command authority.