Skip to content

Dashboard distribution and marketplace expectations ​

Marketplace and distribution architecture is described in docs/marketplace_spec.md.

This extension specification treats distribution as a governance and lifecycle layer on top of runtime packaging.

13.1 Documentation requirements for distributed extensions ​

Distributed extensions must clearly disclose:

  • publisher/author identity
  • version and compatibility
  • requested permissions
  • whether native code is included
  • whether email send is used
  • whether dashboard resources are used
  • every required or recommended model, its external source, and why it is used
  • whether tools/servers/MCP-like resources are used
  • persistence behavior
  • data retention and uninstall behavior

For model recommendations, publishers must also disclose that model records are added to workspace inventory, group linking and local file download remain separate administrator actions, local model licensing and device requirements, remote-provider data handling and costs, and that uninstalling the extension does not remove provisioned models. Follow Model recommendations.

13.2 Lifecycle topics that must be documented ​

  • publication
  • review/approval
  • installation scope
  • updates
  • revocation
  • audit logging

13.3 Trust model ​

When dashboard distribution is used, package identity, signing, and update continuity must be treated as first-class concerns, consistent with the goals described in docs/marketplace_spec.md.

ISA Warden extension specification