Grouper Product Roadmap

Grouper Product Roadmap

Grouper Product Roadmap

This roadmap sketches substantial and signal functional enhancements to Grouper, and to align at least some of them with future releases. It is (always!) a work in progress, subject to the considerations and requirements of participants in the Grouper Working Group. It is also a proposition: it represents the default plan that the Grouper core developers will attempt to implement.
Items that have fallen off of the roadmap appear further below with some explanation as to why.

Grouper Version Support

Grouper developers offer support to the versions released in the last 3 months or the latest version in the active major versions (currently 4.x, 5.x). 

 

See Grouper Versioning and Support info here.

Release

Tentative date or time frame

Support

Notes

v1.6

Released June 2010

None

 

v2.0

Released September 2011

None

 

v2.1

Released March 2012

None

 

v2.2

Released July 2014

None

 

v2.3

Released April 2016

None

 

v2.4

Released August 2018

None

 

v2.5

Released April 2020

None

 

v2.6

Released September 2021

None

Has both new provisioning and subject sources as well as old

v4

Released March 2023

Stable release

Is same as v2.6, but using semantic versioning

v5

Released October 2023

Stable release

Will only have new provisioners

6.0

Released February 2026

Stable release

Stable version of v5

These are gone in v6 Apache, shib SP WS SOAP Non-provisioning-framework provisioners
  • googleapps-google-provisioner

  • grouperAtlassianConnector

  • grouper-aws-changelog

  • grouper-azure

  • grouper-box

  • grouper-duo

  • grouperKimConnector

  • grouper-pspng

  • grouper-remedy

  • grouper-remedyDigitalMarketplace

  • grouperScim

  • grouper-shib

  • grouper-tierApiAuthz

  • grouper-tier-scim

  • grouper-installer

These will still be in Grouper going forward All provisioning framework connectors Custom change log consumers Messaging connectors
  • grouper-messaging-activemq

  • grouper-messaging-aws

  • grouper-messaging-rabbitmq

v7

Estimated Q4 2026

Not released

Will redo how data is stored in the database in order to make things faster and use fewer resources

Will only have new data field subject sources

Work on migrating away from legacy provisioners, SOAP, and Apache in v4.

 

Release

Item

Description

Release

Item

Description

v7

Grouper Oauth 2.1

Originally this is tightly coupled with MCP but could be leveraged for other things in the future.  Grouper is an Oauth 2.1 Authorization server which can allow users to approve scopes for access tokens.

v7

Grouper MCP

AI MCP server on top of Grouper Oauth and Grouper WS.

v7

Provisioning activity and auditing

Write audits to the provisioning audit table and read that from UI.  Errors to audit table too?

v7

External system usage

Report on external systems to see where they are used

v7

Add more ABAC / data field features

Add visualization, attribute resolver, and renames.

v7

Implement centralized SQL batch sizes

See what the batch size is for each DB vendor and set a default which can be overridden.  Adjust hardcoded batch sizes with these defaults

v7

External system documentation in wizard

For each external system document the specifics in the wizard

v7

Upgrade JS libraries

JS libraries

v7

Remove legacy subject source configs

Only new subject source available

v7

Add bulk operations

Make bulk operations faster, e.g. creating or deleting a list of groups, adding or removing a list of memberships.  Add bulk hooks

v7

Redesign Grouper DDL

Reduce size, improve efficiency, move to single purpose tables/structure.  Simple integer foreign keys (sequence or auto increment).  Simple integer enums.  Compact core tables with external auxiliary tables.

v7

Performance diagnostics

Administrative function to measure and diagnose the performance of a deployment

v7

Cache redesign

Analyze and improve how Grouper caches objects in and out of Hibernate.  Simply the subject API

v7

Remove Voot

Remove the Voot provisioner

v7

Upgrade Groovy

Major version upgrade of Groovy, for new features

v7

Reorganize Git source

Reorganize Git source directories to be more standard (GRP-5134)

v9

Revisit Grouper service registry

Identify services in grouper.  Make them easy to see, join, manage, document, attest, etc.
https://docs.google.com/document/d/1zV2kuAKOwoBFIf4GIpiQt6-NFsVkdbYdagDjGcJ7efQ/edit

v9

Re-write Grouper WS

Either use SCIM or more targeted REST/JSON to streamline operations.  Proxy from old to new so legacy clients are supported.  New operations will not have SOAP or XML.  SOAP jars will no longer be in Grouper (proxy to another shim project)

?

GSH loader

Allow a loader to be a GSH script to load groups and memberships (like SQL)

?

Migrate Grouper git

For consistency, reporting, licensing reasons, Internet2 would like the Grouper git repo to be in its enterprise account instead of public git

?

Simplify UI

Make UI task oriented and easy to use for various types of users

?

Integrate connid

midpoint uses connid for provisioning.  This is a standard.  We would like Grouper to be able to load from and provision to connid connectors.  We would also like to migrate our (non-pspng) connectors (e.g. duo, box, etc) to connid (if not there already) and share with midpoint.

?

Improve notifications

support people, groups, and email lists.  Individual email addresses are problematic.  Add ability to batch emails.  Log emails (temporarily).  User can control preferences.  Notify configure on groups.
Grouper email notifications

?

Curated groups

Add features to support Duke presentation
https://meetings.internet2.edu/media/medialibrary/2019/12/05/20191211-mckee-paranoidiam_1.pdf

?

Membership constraints

Allow memberships to be able to be constrained for certain reasons, when those conditions are met, enable the membership, else disable. And keep the existing enabled/disabled dates if applicable

?

GraphQL WS interface

Implement graphQL on web services

?

Custom Grouper types

Allow institution specific types to be added.  Get requirements from community.

?

Daily report refactor

Refactor the Grouper "daily" report.  make it a dashboard on UI.  Keep calculations in attributes if they arent already there with instrumentation.  See what features we can use from Michael Gettes dashboard.  See what features from Chad Redman email on April 9, 2019 with his daily report features

?

Changelog improvements

Allow change log consumers or message publishers to process messages before the single threaded "change log temp" processor completes.

Or, not that change log temp is quicker, allow change log consumers to keep track of which messages they have processed so messages can be processed out of order

?

Register for notifications

Add ability for users to register to be notified of changes to specified objects. Note, there are rules to email users about changes to memberships

?

Provision lifecycle events

Events (such as admission, enrollment, new hire, etc.) must trigger lifecycle stage transitions, role changes, affiliation changes, etc.  Those can then cause other events such as service eligibility.  Lifecycle changes or affiliations all precipitate a need for provisioning wherein roles are mapped to services / entitlements.

?

Workflow state groups

The solution must support high level workflows between states. Group memberships transitioning among workflow state groups

?

Separation of duties

The solution must anticipate the possibility of conflicting roles in the case of multiple personae. Also allow overrides of separation of duties

?

Conflicting roles

The solutions must take into consideration that conflicting grants of authority, eg, one source indicating a grant of access and another a denial of access, must be resolvable according to the needs of each application or service context

?

Handle multiple roles

The solutions must enable individuals to have multiple roles/affiliations/relationships/whatever with the institution, each with its own lifecycle and overlapping set of access privileges needed to undertake each role. Statefulness (persistence and preservation of state) must permeate the design goals of all solution components in order to correctly and efficiently manage their access over the course of these multiple lifecycles

?

Rules on individual membership

An individual membership could have a rule that it is dependent on memberships in another group for example

?

Add remaining attribute/permission operations to WS

Add permission hierarchy services for roles, actions. Limits? Any other attribute permission services?

?

Add dropbox endpoint to provisioning

 

?

UI warn, restrict, or schedule large operations

If adding a group to another group, maybe warn, restrict, notify user that the operation will take a while to provision. Or schedule this for later?

?

Copy entitlements to another user

Copy entitlements to another user. Optionally include start and end dates

?

Automatically clean various things

If a group is marked as a composite ad hoc list (and/or maybe includes / excludes), then if the membership is no longer relevant, then set an end date for some time in the future. Optionally notify. This applies to individual permissions as well. Automatically or manually clean up redundant privs (if assigned to group and individual). Automatically or manually clean up redundant memberships (group and individual)

?

Add high level help or how tos

For admins or users etc

?

 

Direct/indirect should show on policy group

?

 

Security model - documentation and UI opportunities - wizard?

?

 

Can application owners see reference group?  via attributes

?

WCAG accessibility certification

Various accessibility analyses have been done by institutions. Changes have been implemented in the UI when reported. There is not yet a formal WCAG compliance certification (e.g. WCAG 2.0, 2.1). Customers needing an RFP to implement Grouper or that have requirements for a WCAG report could benefit from one.

?

Upgrade bootstrap

Major upgrade to bootstrap UI CSS and JS, or migrate to something else

?

Reorganize Git source

Reorganize Git source directories to be more standard (GRP-5134)

On-going

Rewrite Grouper wiki

Remove old docs and make sure missing docs are added

On-going

Update third party libraries

Update third party libraries to the latest version

On-going

Update training videos

Go through training videos and either keep, re-record, annotate, or delete. Identify new training videos to make

On-going

Grouper Core enhancement

Continue adding capabilities to meet requirements from the field.

On-going

Community contributions

Solicit and publicize community contributions of extensions and complements to Grouper.

Not yet assigned

More provisioning connectors

Add further connectors to reflect specified group, membership, role, and permission information into external systems and services. Include Google provisioning (from the Unicon contribution to the PSPNG)

Not yet assigned

Scaling REST webservice

A page in the Administration guide, Grouper always available web services and client, demonstrates one way to provide always available services using a specialized client.  The CIFER REST web service will need the server-side capability to provide that always-available functionality.  In addition the REST API should be able to access multiple, read-only caches so it can efficiently handle any increase in query requests, most of which will not need to directly access the primary database. PSPNG should be able to provision to a database table, and WS should be able to read from that table (or tables) for simple operations.

Whatever happened to ... ?

A brief explanation of why some things seem to have disappeared from earlier versions of this roadmap.

What Happened?

Item

Description

What Happened?

Item

Description

v4 (DONE)

Freshservice requester provisioner

Manage Freshservice requesters and groups

v5 (DONE)

User lifecycle events

Configure lifecycle events.  Capture events efficiently.  Configure policies and assign to groups.  Take actions when user lifecycle events are affected by policies.

v5 (DONE)

Remove unneeded externalized text

Remove admin and lite UI externalized text

v5 (DONE)

Upgrade Java libraries

Update Java libraries to latest stable versions

v5 (DONE)

Consolidate utils classes

JEXL translations have different utils classes in scope.  These should be harmonized.

v5 (DONE)

Group summary screen

The main group screen should have a "Summary" tab, which does not show actual members, but will show a summary of the group, e.g. how many members (direct or indirect), types, provisioning, attributes, rules, attestation, loading, etc.  The summary screen will have links to the details for various things

v5 (DONE)

Configure subject source from data fields

Subject information should be configured as data fields and configure a subject source based on data fields.  The subject source is now in the Grouper database and does not need an external dependency.  The performance will be improved and the searching is standardized (instead of different for SQL vs LDAP).

v5 (DONE)

Explore potential of AI to improve Grouper functions

Explore AI calling web services with basic auth, using AI GSH Template to call script, set up a training file in git 

v5 (DONE)

Add more ABAC / data field features

Add natural language, self-documentation, diagnostics, and secure editing.

v5 (DONE)

Incremental scripted groups

Manage dependencies and real time changes for ABAC scripted groups.  

v5 (DONE)

Fix pac4j include with releases

Build Grouper authentication jar (minimal) and assemble the larger plugin jar when the container is built.  Include the authentication plugin jar in container for easy use.

v5 (DONE)

Upgrade http client

Upgrade to supported HTTP client in all Grouper modules

v5 (DONE)

Installer in docker, remove installer java module

Move the "installer logic" to be in the Dockerfile

v4 (DONE)

Min group membership size

In loader jobs and just on groups have min group sizes
https://grouper.atlassian.net/browse/GRP-2388

v5 (DONE)

Add group graph

Add group membership information for a user in the visualization.

v5 (DONE)

Normalize UUIDs, add idIndexes

For core objects which do not have idIndex, add.  Normalize UUIDs so they are lower case without dash.

v4 (DONE)

Playwright in UI to sanity test Grouper

Add Playwright in UI so Grouper can be sanity tested on upgrade (or whenever)

v4 (DONE)

Make a translation utility on UI

Make a translation utility on UI to test various things...  use GSH for this

v4 (DONE)

Grouper WS OpenAPI

Document the WS API with Swagger JSON.  WS will host a "dynamic" and customizable WS API page.  Explore client generation.