Cut out of the #11632 SCIM epic by its owning domain:services seat and filed for the spec seat, because the epic says so in its own scope text:
spec: field-level parity pass between SCIMGroupSchema and stable's group wire shape (unmeasured so far); packages/spec work goes to the spec seat per single-owner rule.
⛔ The services lane has zero packages/spec ownership. This card is filed, not taken. No pm:queue — grading is triage's field.
The ruled direction this works within
Maintainer, 2026-08-24, live PM chat on #3653 (「os#3653 立项迁移」). The epic records the consequence: #3653's question A is answered implement — "the SCIMGroup family becomes true through this migration, not through retirement."
⇒ This is a parity pass, not a retirement question. That part is settled.
What is actually unmeasured — and what is not
The epic marks the field-level diff "unmeasured so far", and it still is. But two things around it have been measured since the epic was written, by the repaired parity gate (PR #11429, merged 2026-08-23, fixes #11380) running against published @better-auth/scim@1.7.1:
| models |
|---|
| gained on stable | scimConnectionBinding, scimIdentityTombstone, scimProjectionGrant, scimSubject, scimUser |
| lost on stable | scimGroupRole, scimGroupRoleGrant |
| kept | scimGroup, scimGroupMember |
⭐ scimGroup and scimGroupMember are in the KEPT column — they exist on both the pinned 1.7.0-rc.1 and stable. So this card is genuinely a field-level question (do the columns agree?), not a model-existence one. Whoever takes it does not need to establish that the models survive; that is measured.
⚠️ Read the model names as what the gate reports, not as spec identifiers. Mapping them onto SCIMGroupSchema's shape is part of this card's work.
Sequencing — this is FIRST, and it does not wait
The epic's Discipline section says "spec first". Concretely:
Not measured
- The field-level diff itself. That is this card's deliverable. Nothing in this repo has compared
SCIMGroupSchema's fields against stable's group wire shape. - Whether the parity result forces any authorable-surface movement in
packages/spec. Unknown until the diff exists, and it is the spec seat's call either way.
One standing operational note that rides the whole migration
⚠️ Not this card's work, but it governs the window: SCIM-enabled deployments must not let the IdP push groups until the migration lands, and on migration day every SCIM-enabled deployment's IdP must reissue its token (unsalted SHA-256 → keyed HMAC; digests are not portable on any path). That is an operational action with a human owner, tracked on the epic.
Refs: #11632 (the epic, leg 3) · #3653 (decision anchor + the seven-model measurements) · #11380 / PR #11429 (the gate repair that produced the model diff above) · #11693 (the sys_scim_provider disposition — parallel, not a prerequisite) · ADR-0071
Cut out of the #11632 SCIM epic by its owning
domain:servicesseat and filed for the spec seat, because the epic says so in its own scope text:⛔ The services lane has zero
packages/specownership. This card is filed, not taken. Nopm:queue— grading is triage's field.The ruled direction this works within
Maintainer, 2026-08-24, live PM chat on #3653 (「os#3653 立项迁移」). The epic records the consequence: #3653's question A is answered
implement— "theSCIMGroupfamily becomes true through this migration, not through retirement."⇒ This is a parity pass, not a retirement question. That part is settled.
What is actually unmeasured — and what is not
The epic marks the field-level diff "unmeasured so far", and it still is. But two things around it have been measured since the epic was written, by the repaired parity gate (PR #11429, merged 2026-08-23, fixes #11380) running against published
@better-auth/scim@1.7.1:scimConnectionBinding,scimIdentityTombstone,scimProjectionGrant,scimSubject,scimUserscimGroupRole,scimGroupRoleGrantscimGroup,scimGroupMember⭐
scimGroupandscimGroupMemberare in the KEPT column — they exist on both the pinned1.7.0-rc.1and stable. So this card is genuinely a field-level question (do the columns agree?), not a model-existence one. Whoever takes it does not need to establish that the models survive; that is measured.SCIMGroupSchema's shape is part of this card's work.Sequencing — this is FIRST, and it does not wait
The epic's Discipline section says "spec first". Concretely:
sys_scim_provider's disposition under the stable @better-auth/scim migration — the upstream model it mirrors no longer exists #11693 (thesys_scim_providerdisposition). That decision is about a different object;scimProvideris in neither the kept nor the group family here.main: PR fix(plugin-auth): make the SCIM parity gate reach its model diff on stable @better-auth/scim #11429's constructor fix landed independently (not absorbed), so the gate that will report parity failures actually reaches its diff instead of dying in collection.Blocked-by:pointing here, per the epic's contract-first chain — not the reverse.Not measured
SCIMGroupSchema's fields against stable's group wire shape.packages/spec. Unknown until the diff exists, and it is the spec seat's call either way.One standing operational note that rides the whole migration
Refs: #11632 (the epic, leg 3) · #3653 (decision anchor + the seven-model measurements) · #11380 / PR #11429 (the gate repair that produced the model diff above) · #11693 (the
sys_scim_providerdisposition — parallel, not a prerequisite) · ADR-0071