- cross-signing (so users verify their own devices themselves, and you verify users only once by verifying their public key, regardless of how many times they add or update devices)
- and key backup (so moving between devices doesn't need manual polling for other devices' keys the first time for decrypting messages)
would be a great step forward. Those are there, but they are disabled by default yet, which is a disservice.