# Monthly adopters meeting: 2021 Dec 1st (combined Nov & Dec)

**URL:** <https://we.hypha.app/t/monthly-adopters-meeting-2021-dec-1st-combined-nov-dec/208>\
**Category:** Adopters\
**Created:** [November 9, 2021, 12:58pm UTC](https://we.hypha.app/t/monthly-adopters-meeting-2021-dec-1st-combined-nov-dec/208 "2021-11-09T12:58:55Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![eriol](https://yyz2.discourse-cdn.com/flex036/user_avatar/we.hypha.app/eriol/32/39_2.png) [@eriol](https://we.hypha.app/u/eriol)\
**Post date:** [December 3, 2021, 1:25pm UTC](https://we.hypha.app/t/monthly-adopters-meeting-2021-dec-1st-combined-nov-dec/208/3 "2021-12-03T13:25:07Z")

</div>

Attending: Eriol, Chelsea, Bernard, Fredrik, Dan, Rosy, Chris Zubak-Skees

Apologies: Allan, Karl (maybe),

**Agenda**

> [@Monthly adopters meeting: 2021 Dec 1st (combined Nov & Dec)](https://we.hypha.app/t/monthly-adopters-meeting-2021-dec-1st-combined-nov-dec/208):
>
> Logistics 2021-12-01T15:30:00Z (UTC) → 2021-12-01T17:00:00Z (UTC) tv Google meet room: [https://meet.google.com/bnj-yvrx-ybn](https://meet.google.com/bnj-yvrx-ybn) If you’d like access, send a message to the [@maintainers](https://we.hypha.app/groups/maintainers) group. If you’d like to attend, please email dixie@hypha.app From there, you’ll get an invite with meeting details. Real-time chat Agenda handshake Intros computer Review what’s changed/completed in the past month (See new [releases](https://github.com/HyphaApp/hypha/releases)) Review of work expected to happen in the coming monthcomputer …

- Anyone needs any specific time to discuss ongoing work?

- Add here

- Intros (if any new folks)

- We did mini updates on new things we’ve learned or done lately including, India payments, healthcare, open source servers, boat repair, fish care, Parent park comms, smokeless incense.

- Review what’s changed/completed in the past month

(See new releases: [Releases · HyphaApp/hypha · GitHub](https://github.com/HyphaApp/hypha/releases))

- Frederik notes that only 2 releases have been done, given finance and compliance work for OTF. Fixed some date widgets in Wagtail. Sidebar detail view is now ordered a bit differently. Have limited tokens to only access public API. More work is needed for “headless” authentication. Vendors can set up bank accounts, so staff can review/ask for corrections and coordinate with finance team and financial system.

- Grateful for Chris’s fixes

**Review of work expected to happen in the coming month**

- Dev

- Security issues

- Public issues: [[META/EPIC] Security Audit recommendations from Aug 2021 · Issue #2642 · HyphaApp/hypha · GitHub](https://github.com/HyphaApp/hypha/issues/2642)

- Private issues (potentially exploitable:[https://github.com/HyphaApp/hypha-issues/issues](https://github.com/HyphaApp/hypha-issues/issues))

- See a mini burndown of completed issues in the we.hypha post:[https://we.hypha.app/t/penetration-test-report-from-radically-open-security/140/8](https://we.hypha.app/t/penetration-test-report-from-radically-open-security/140/8) (locked to security role in the forum adopters maintainers should have access)

- examples of work: 2-factor authentication, requiring PW to make changes. Now this work is urgent, then finance and compliance work.

- Finance work (OTF)

- Next step: contracting and contract workflow. Approval form where staff can add needed info. Aims to be flexible, to work with both large and small orgs.

- Design

- Compliance work, PAF (OTF)

- Working on making compliance steps flexible for different size orgs.

- Trying to learn more about OS docu-sign, as some folks only want to

- ACTION: put Chris Smith (G1FEF) in touch with Frederik and Bernard (Rosy)

- Files tab: [[Files tab spike]: what does the files tab need to do for users · Issue #2634 · HyphaApp/hypha · GitHub](https://github.com/HyphaApp/hypha/issues/2634) (waiting on OTF prioritisation)

- Things like contracts will go here!

- Reporting (connected to PM updates): [Miro](https://miro.com/app/board/o9J_l5LQgJ0=/) & [Reporting functionality: Discussion and clarity - #14 by eriol](https://we.hypha.app/t/reporting-functionality-discussion-and-clarity/162/14)

- Got feedback re: “boring video” that the concept works

- PM

- Reporting feature feasibility scoping started and located here: Feasibility Review Template - M&E and Reporting - Adopters Nov & Dec 2021 - Google Sheets: [Feasibility Review Template - M&E and Reporting - Adopters Nov & Dec 2021 & Jan 2022 - Google Sheets](https://docs.google.com/spreadsheets/d/1-anh9NM8CyChGX2IjpJjl81P-wdLVYJHlJr3Q0J0X4Q/edit?pli=1#gid=1610025234)

- Waiting on some comments from Allen re: DDP’s perspective on reporting, ideally to be received by the end of the week.

- Eriol, Frederik, and Bernard did some feasibility scoping (linked above). Eriol shares screen to go through list.

- Next stage of spreadsheet: need to get some questions answered from adopters.

- Rosy asks about answering questions - how to share answers? Eriol recommends starting with comments in the doc and then moving to larger conversation if needed.

- Submitting issues

- how it currently happens and how it could be changed

- Wishlist issue process pitch - mini demo

- Reporting bugs

- proposal to use [marker.io](http://marker.io): a browser plugin that allows the reporting of a bug/issue directly from user’s browser by creating video/audio

- This saves the need to use github

- Docs

- Organizational changes - user-based instead of task-based, check it out here: [https://docs.hypha.app/](https://docs.hypha.app/)

- Populating blank pages - please @ Emily (in we.hypha.app) with suggestions for pages you’d like to see

- Soliciting contributors (add content to pages!) or testers (read documentation and see if you can achieve the goal laid out in the doc, give feedback on content/structure of individual pages)

- Adopters

- opportunity for them to talk about anything Hypha-related they’re working on this month.

- No updates this month

**Review new challenges/insights/issues identified**

- **@allan** might take us through DDP’s grant workflow if he is available - In 2022 we’ll catch up with Allan

- Let’s talk about what Adopters want to happen with security audit details: [https://we.hypha.app/t/penetration-test-report-from-radically-open-security/140](https://we.hypha.app/t/penetration-test-report-from-radically-open-security/140)

- If security issues are found after a security audit, there needs to be a “period of quietness” during which critical fixes (i.e. can be used to exploit Hypha instances) are made. Proposal is 6 weeks.

- During this 6 weeks the issues are fixes and adopters are updated on progress.

- How long post-core implementation of recommendations do Adopters want to ensure their security is good, parity etc.?

- most recent audit here: [https://www.hypha.app/reports/Radically\_Open\_Security\_2021\_Hypha.pdf](https://www.hypha.app/reports/Radically_Open_Security_2021_Hypha.pdf)

- What level of openness of publication of the security audit do Adopters want? [https://we.hypha.app/t/penetration-test-report-from-radically-open-security/140/5](https://we.hypha.app/t/penetration-test-report-from-radically-open-security/140/5)

- API for open calls - public & private quick update and call for future conversations (API for open calls - tokens, access and how adopters want to discuss): [API for open calls - tokens, access and how adopters want to discuss](https://we.hypha.app/t/api-for-open-calls-tokens-access-and-how-adopters-want-to-discuss/213)

**What else do folks want to discuss? Reply with agenda items!**

- Documentation: Adopter preference question & configuration method

- Do any adopters want Reviewers to be able to contact applicants directly, within Hypha or outside of it, like via email (or conversely, want Reviewers _not_ to see applicant info/be able to contact applicant)?

- Not an existing functionality

- From fredrik, not something that any adopters have wanted

- Is it (it being showing applicant email to reviewers, and/or allowing reviewer-applicant communication within Hypha) a customizable setting?

- “being showing applicant email to reviewers”

- Not currently available

- Fredrik: discussion about making some fields viewable by Hypha users with the correct permissions

- “allowing reviewer-applicant communication within Hypha”

- open an issue

- allowing/disallow reviewers to comment on applications - Per role- on particular applications etc. Reviewer role has not comment posting permission.

- AP: Eriol can ask Allan if they implemented on the FE removal of some PII fields to be more unbiased in selection.

- @bernard says there is a way for applicants to not be visible to reviewers, but doesn’t remember how/where it’s done.

- @dluong, do you remember whether this is the case? And if so, how we do it? \< Di responded in the Doc WG we.hypha post: [API for open calls - tokens, access and how adopters want to discuss](https://we.hypha.app/t/api-for-open-calls-tokens-access-and-how-adopters-want-to-discuss/213)

- Hypha Summit 2022 - wanted or not wanted? - Pushed to next adopters call

- Who pays/how do we pay for a summit?

- How long and what topics? e.g. Governance, Upstream/Downstream processes if and when deployments of Hypha are **not updated through the main repo,** Stakeholder agreements. Example: [Community Pledge v2 - January 2020 - Governance - Open Food Network Community](https://community.openfoodnetwork.org/t/community-pledge-v2-january-2020/1847)

---

_[View the full topic](https://we.hypha.app/t/monthly-adopters-meeting-2021-dec-1st-combined-nov-dec/208)._
