Roadmap
Current release: v1.5.0. The README on GitHub carries a shorter version of this, and the changelog has the per-release detail.
Shipped
- Mobile and wearable apps - Android on the Play Store with Wear OS companion and complication. iOS on the App Store with watchOS companion and complication.
- Front-change notifications - web push, mobile push (FCM + APNs), generic webhook (JSON / Discord / Slack / plaintext), ntfy, and Pushover. Per-channel filters with three-layer member visibility (base + group rules + per-member overrides), payload sensitivity, debounce, and quiet hours.
- Realtime front stream - a Server-Sent Events endpoint that pushes front changes as they happen, for home automation (Home Assistant, Node-RED) and live UI updates. Outbound-only, so a LAN-only consumer works without any inbound reachability.
- Home Assistant integration - sheaf-ha surfaces your system as HA entities, with per-member sensors and switches, automation events, and services to change the front. Early, and installed via HACS as a custom repository.
- Polls - cross-system voting with audit log, fronter attribution, deadlines, and auto-purge
- Messages - global system board and per-member walls with reply chains and edit history
- Notes - per-member and per-system encrypted scratchpads (markdown)
- Journals - per-member or system-wide markdown entries, encrypted, with versioned edit history
- Reminders - daily / weekly / monthly pings, or fire X minutes after a specific member fronts, with member-scoped queueing
- Analytics - per-member front time, percent of window, session count, longest session, hour-of-day distribution (7d / 30d / 90d / 1y)
- Public profiles and share links - share a curated slice of your system with people outside it, built around views (exactly which members, fields, groups and relationships are shown) and grants (a public profile, or a revocable and rotatable opaque link). Off unless the operator enables it, and off for you until you publish. Per-member never-shareable and fronting-private guards, privacy levels on members, groups, fields and relationships with your system setting as the ceiling, publishing gated behind re-auth and the System Safety grace period, no external images or referrers on shared pages, and a preview that shows you exactly what a visitor gets before anyone else sees it. See the features page.
- Relationships - typed relationships between members and between subsystems (partner, parent/child, protector, or your own), with symmetric / directional / either direction modes, per-type colours, per-relationship privacy, and a self-arranging system graph you can edit in place
- Ordering for groups and custom fields - arrange them how you like; the order holds everywhere they are listed, survives a backup restore, and carries through to shared pages
- Subgroups - groups nest up to 8 levels, with a drag-to-reparent tree and subtree-inclusive filtering
- Archived members - soft-hide a member from lists and pickers without losing their name anywhere it appears in history
- Revision history and pinning - tier-aware retention caps; pin revisions to exempt from trim, with optional re-auth + grace on unpin
- Front-history retention - opt-in per-system window that ages out old closed fronts, as a privacy control rather than a tier limit, with an import grace period and a deferred re-auth-gated countdown on tightening
- System Safety - configurable grace period and re-auth (password / TOTP) on destructive actions
- Custom fronts - non-counting fronting entities so "Asleep" / "Away" don't inflate member counts
- Status notes - encrypted free-text note per fronting period
- Display timezone and date format - per-account preferences that sync across devices, with per-device override
- Importers - PluralKit (file or live via
pk;token), SimplyPlural, Tupperbox, PluralSpace, Prism (encrypted.prismexports), and Ampersand. All deduplicate against existing roster on re-import, and the preview tells you what will be shortened or capped before you commit. - PluralPort v0.1 import and export - the interchange format formerly called OpenPlural, as both a single JSON document and a
.pluralport.zipbundle with image bytes. Files written against the old name still import. Sheaf-specific data rides in a namespaced extensions key so a round-trip is lossless, and other apps' data that Sheaf can't model is preserved on import and re-emitted on export. - Round-trip backup - the Article 20 export imports back as-is, including image bytes, so a backup-and-restore (or a migration to another instance) keeps everything
- Front-history export - fronting history on its own as CSV, JSON, or ICS (drop it into a calendar app)
- Account activity log - a curated record of consequential account actions and automated actions on your data, content-free and IP-free
- Verifiable builds - sigstore/cosign signed Docker images plus Subresource Integrity for the frontend bundle
- Storage quotas - per-tier account-wide budget
- Orphaned file cleanup - images uploaded but never attached
- API keys with granular scopes, for scripts and integrations
- Admin UI - user management, audit log, server announcements, emergency-support tools (System Safety reset, pending bypass, soft-ban with auto-restore, force-rotate API keys, session terminate)
- Abuse investigation tooling - append-only security-event log with IP and CIDR lookup, a credential-stuffing view, and per-account auth timelines, all bounded by a short retention window and audited on use
- Operator kill switch - halt every data-deleting background job in one move while investigating a retention issue
- Signed image URLs with S3 presign support (hotlink protection)
- Prometheus-compatible
/metricsendpoint - see METRICS.md - All-in-one Docker image - backend, web UI, and a reverse proxy with automatic HTTPS in one container, including a Cloudflare Tunnel path for a box with no public IP
- Multi-replica deployments - background loops are coordinated by Postgres advisory-lock leader election; standbys take over within seconds of a leader dying
Planned
- Named fronts - save a named combination of members, searchable from the start-front dialog
- CLI similar to simplyplural-cli
- PluralKit bidirectional sync - on top of the existing one-shot import
- Friend / trust system - cross-system visibility controls
- Per-field-per-member privacy overrides
- Custom-defined user tiers by server admin, replacing the placeholder free/plus/selfhosted tiers
- Terraform module for cloud deployment
- More 2FA methods - WebAuthn / YubiKey, email OTP as a "better than nothing" fallback
- Alternate secrets management - AWS Secrets Manager, Vault, others
- Accessibility improvements - image alt-text support, and more
Have something you'd like to see? Open an issue or drop into Discord.