Roadmap¶
TOVIO is built bottom-up, in phases. Each layer is only as trustworthy as the one beneath it,
so we ship them in order. This page is the high-level shape for users as of 2026-09-08, the date of
the repository's docs/current-state.md ledger. Phase labels describe subsystem milestones, not blanket
conformance; implementation details and cross-phase gaps live in that ledger, and its dated As of header
is the authority whenever this page and the ledger differ.
Ordering is firm; dates are guidance
The sequence below is normative --- it follows hard dependencies that can't be reordered. The rough timeframes are guidance only, and phases overlap at the seams. We don't pin calendar dates.
At a glance¶
| Phase | Theme | What you get |
|---|---|---|
| 0 — Foundation | Offline core | Complete. Runnable offline core under its documented profile. |
| 1 — Permissions | Cryptographic per-file access | Done. Tier-0/Tier-1 encryption, policy, access, identity, keys, and signed audit. |
| 2 — Agents | Capability tokens + MCP | Complete. CLI, Node SDK/bindings, MCP reads/writes, provenance, and advisory coordination are implemented; publication is Phase 5. |
| 3 — Sync & Forge | Distributed collaboration | Complete. Native/REST partial sync, the Forge, direct peers, shared-volume HA, cross-Forge coordination, and Git bridge pass the ADR-0074 reference profile. |
| 4 — Semantic | Optional intelligence | Complete. Four-language symbol graph, semantic landing, sealed indexes, behavioral registry, risk assessment, and resolver seam. |
| 5 — Ecosystem & scale | Hardening & reach | In progress. M5.0 contracts/gates complete; hosted, enterprise, productization, audit, publication, and evidence work remains. |
The phases¶
Foundation --- the offline core¶
Status: complete under the documented Phase 0 profile. Safe automatic checkout and authenticated typed obliteration are implemented. Phase 5 owns additive storage hardening and production evidence.
A working, offline, content-addressed VCS you can use as a drop-in for the basic Git loop.
This is the runnable base. You can init a repo, commit, lane, switch, diff, and view history with
zero network. Highlights:
- No staging area --- your working copy is always the current change.
- Local operation-log undo --- supported recorded mutations reverse locally, not just commits; irreversible maintenance and external side effects are explicitly excluded.
- Binary parity --- big files are chunked and deduplicated; no Git LFS.
- Change IDs that survive history rewriting, distinct from commit hashes.
- First-class conflicts and CRDT lanes --- no "diverged history" errors.
- Git import --- bring an existing repo in with
tovio git import. - Zero-to-first-commit in under a minute, with an interactive
tovio quickstart.
Permissions --- cryptographic per-file access¶
Status: done for the v1 Tier-0/Tier-1 target. Protected-read audit emission is wired across CLI and
Node/MCP disclosure edges; access request, policy test, policy history, authenticated export, archive
checkpoints, and retention controls are implemented in their documented profiles. Publication and external
evidence remain Phase 5 work. Tier-2 CP-ABE has passed its enterprise KA conformance and internal-review
gate, but remains behind the separately licensed, default-off release boundary; threshold/KMS/HSM authority
remains a later Enterprise profile.
Commit a secret and prove a second identity can't decrypt it --- even with the full ciphertext in hand.
The headline differentiator. You mark sensitive paths with a policy; those files are encrypted at snapshot time, before they ever touch a tracked tree.
- Solo mode --- zero-setup
ageencryption rooted in your own key. - Team mode --- the hybrid envelope: content encrypted once, the data key wrapped per authorized identity. Grant adds a wrapped key; revoke rotates the key.
- The Key Authority is an authorization oracle --- it decides whose keys are wrapped, and never sees plaintext or content keys.
- A signed, replicated audit log you can verify offline.
- IDE and CI presence --- a VS Code extension (SCM status, quick diff, rationale hover, lane switching, conflicts, health) and a CI/CD bridge. Neither is published as a public package yet; that is Phase 5.
The proof point: a developer commits config/prod.env under a policy, a teammate without clearance
clones the repo, and the file is unreadable to them --- enforced by math, not a server.
Agents --- the control plane¶
Status: complete under the documented Phase 2 profile. Protected diff/conflict/source-move operations, region picks, session correlation, the CLI wrapper, stdio and Streamable HTTP, effective-scope/status projection, old-reader-key rotation fallback, full-chain delegated-session reconnect, and tool-manifest binding are implemented. npm publication and its clean-runner evidence remain Phase 5 work.
AI agents become first-class, capability-scoped, audited participants.
- Capability tokens --- signed certificates scoping an agent's paths, clearance, allowed operations, and expiry.
- No clearance, no key --- an agent without
secret_clearanceis never wrapped a key for a protected object, even within its path scope. - Path scope enforced first --- out-of-scope access fails before any decryption is attempted.
- An MCP server that validates the token on every tool call and never exposes destructive ops.
- Provenance on every agent commit --- model, task, and who authorized it.
- Sub-token delegation --- agents can mint and issuance-verify narrower-or-equal tokens. A returned leaf cannot open a later session until the connection carries or resolves its full chain.
The proof point: a Cursor session is registered, issued a path-scoped token, and demonstrably cannot read a protected object outside its scope.
Sync & Forge --- distributed collaboration¶
Status: complete for the ADR-0074 reference profile. Native and hosted partial sync, convergence, locking, durable Forge collaboration, authenticated cross-Forge meta-land, signed discovery, retention, shared-volume active/standby HA, and the namespaced bidirectional Git bridge are implemented and exercised with production binaries on distinct Docker hosts under an operator CA. Distributed storage and physical load/partition certification belong to Phase 5.
Scale from a single laptop to a real team.
- Full sparse sync --- transfer only the objects you're authorized for and actually need.
- Peer-to-peer sync over a local network or a direct peer, alongside relays and Git remotes.
- The Forge --- one Rust binary, commercially licensed, that stores policy-protected content as ciphertext, while authorized public content, repository metadata, runner inputs, and explicitly disclosed agent context retain their separate trust boundaries. It enforces write policies and serves collaboration, audit, review, and coordination APIs. OCI/Helm publication remains Phase 5 evidence-gated work.
- File and asset locking for unmergeable binaries --- lock grants are arbitrated by the client and the server; no push or land path consults the lock table yet.
- Git interoperability --- import, export, and an explicit bidirectional bridge are built; disjoint namespaces prevent either system from overwriting the other's main history.
- Org governance --- the policy surface and the LDAP/SAML/OIDC/SCIM connectors are built (the connectors are commercial); live-provider federation evidence remains Phase 5 work.
The proof point: two developers work fully offline, create overlapping changes, sync, and converge --- no diverged-history error, no merge blocking.
Semantic --- optional intelligence¶
Status: complete under the documented Phase 4 profile. Rust, TypeScript/JavaScript, Python, and Go indexing, semantic diff and landing, sealed protected symbol shards, and behavioral snapshot/diff/rollback are implemented.
A layer that understands your code's structure --- and never blocks a core operation.
- Symbol-aware diffs --- function-level added/removed/modified, breaking-interface detection.
- Semantic conflict detection --- flag interface conflicts that text diffs miss; auto-resolve logically-independent overlaps.
- A behavioral version registry --- snapshot, diff, and roll back an AI system's behavior (model, prompt templates, tool manifest) independently of code.
This layer is additive and on by default (the semantic build feature; a build without it drops every
symbol-graph code path). TOVIO is fully usable without it: a missing, unbuilt, or failing index degrades to
a text diff, never to an error, and the layer never blocks a core commit.
Ecosystem & scale --- hardening and reach¶
Status: in progress. M5.0 established the two release trains and machine-readable acceptance matrix;
M5.1-M5.8 remain open. A first-party local desktop app (tovio-desktop) and its CLI-parity migration run
as a separate active execution track (ADR-0291, ADR-0292); they do not change the phase labels above.
Production-grade: hosted, audited, and proven at scale.
- A hosted Forge (freemium) on the same engine as the on-premise deployment.
- Deeper IDE plugins, and the packages themselves --- the remaining VS Code surfaces, marketplace publication of both the VS Code extension and the in-tree JetBrains plugin (built at parity with the VS Code extension's everyday surfaces; neither is published yet), and npm publication of the CI bridge.
- Hosted CI execution of imported GitHub Actions workflows on TOVIO compute (ADR-0280) --- the bring-your-own-runner CI bridge is built; the hosted executor is under active implementation.
- Enterprise key management --- threshold (k-of-n) and KMS/HSM-backed Key Authorities remain later, provider- and hardware-evidence-gated profiles.
- CP-ABE (Tier 2) --- the CIRCL TKN20 enterprise KA implementation and its conformance/internal-review gate are complete behind the private release boundary; public-client enablement and release evidence remain closed.
- Independent security review and remediation evidence for the applicable public and commercial surfaces.
- Specification v1.0 published --- every contract promoted from Draft to Stable.
The TOVIO 1.0 train is gated on Tier-0/Tier-1 review remediation, Stable v1 specifications, certified artifacts, and applicable evidence. Tier-2 CP-ABE was promoted onto that train and its enterprise KA conformance/internal-review gate has passed, but no generally available artifact enables it. Threshold/KMS/HSM KA remains the later TOVIO 2.0 Enterprise train; Phase 5 is complete only after both trains pass.
What's deferred --- and what's out of scope¶
Some things are planned but later, and some are deliberately not on the map at all.
Implemented slices that still need acceptance evidence
- The production Tier-2 CP-ABE engine and enterprise KA conformance/internal review are complete behind the Enterprise boundary; public-client enablement, release, migration, and performance evidence remain closed. Threshold recovery and KMS/HSM adapters remain later provider/hardware evidence gates.
- Hosted Forge control-plane and Cloudflare adapter slices exist in the commercial boundary; live-provider, real-cloud migration/failure/restore, scale, disaster-recovery, and hosted-parity evidence remains open.
- The bounded OpenAI-compatible resolver adapter and sealed repository-scoped credentials exist; live-origin, rotation, protected-disclosure, adversarial, performance, and audit evidence remains open.
Deferred product breadth
- Symbol indexing beyond Rust, TypeScript/JavaScript, Python and Go is reached through the extensible language-indexer API rather than shipping in the box (ADR-0031).
- An optional gRPC transport mirroring the REST surface may trail the REST and native binary transports (ADR-0008).
Out of scope for v1.0 (not on this roadmap)
- Bittorrent-style fully-decentralized P2P (the peer-to-peer mode is LAN/direct-peer, not a DHT).
- Blockchain-based policy storage --- signed policy manifests instead.
- A TOVIO-native CI language --- TOVIO imports and runs existing GitHub Actions workflows (the bring-your-own-runner bridge today, hosted execution under ADR-0280) rather than inventing its own.
- Real-time collaborative (Google-Docs-style) editing of file content.
- A GUI as a core v1.0 deliverable, or a hosted GUI client --- the CLI and the API come first, a
first-party local desktop app (
tovio-desktop, ADR-0291) is in scope as an edge, and third-party clients are encouraged. - Transparent, drop-in Git wire-protocol compatibility --- interop is via explicit import, export, the bidirectional bridge, and the Forge's bounded Git smart-HTTP facade.
For how releases are numbered and what counts as a breaking change, see versioning.
Last reviewed September 9, 2026
Suggest an improvement to this page Not for security reports — see disclosure