Expansion Packs
Workspace-scoped add-ons that extend OSuite with identity, security, workflow, trust, and optional commerce capabilities while keeping PCAA as the final authority.
Enable faster, but keep the workspace boundary explicit.
Included packs can be enabled in bulk. Trial-ready packs can start together, while paid add-ons stay attached through workspace billing and quote-driven packs stay outside one-click enablement.
Add-on operating model
Packs change the workspace, not just the catalog.
Core OSuite governance works with zero packs enabled. When a workspace enables a pack, it adds visible capability deltas to governed actions, replay, proof, runtime posture, and buyer-facing evidence.
Exchange model
Curated, signed, and workspace-scoped
OSuite does not expose an open plugin marketplace yet. Every expansion pack is listed with a signed manifest, explicit scopes, and install state so high-compliance teams can enable add-ons without giving up PCAA certificate authority.
Build
Start from the signed plugin SDK template instead of inventing a private manifest schema.
Verify
Every curated entry can be inspected, signed, and verified before a workspace owner enables it.
Operate
Enablement and disablement are captured as workspace audit events, not hidden platform state.
Official expansion packs
Directly enableable inside a workspace.
Curated partners
Useful perimeter and commerce adapters we can install under the same control model.
Strategic watchlist
Tracked closely, but not workspace-installable yet.
Recent expansion pack audit events
Workspace-level enablement and disablement events.