QONTO-WP-0004-T04. Modeled directly on examples/tenant-engine/: one resource type (finance-snapshot), one action (finance.qonto.read), two registered subjects (an agent-harness session identity and the founder's human identity), and a Rego policy gating on resource.system + action + subject.type + tenant match. Tenant capability-role/plan liveness (VEN/CUS) is deliberately NOT encoded here -- that's qonto-assistant's separate tenant-engine live-lookup check, per this package's own scope note. Verified: flex-auth test-policy (6 rego tests + 6 fixtures, all pass), load-registry, and CLI check for both an allow and a deny case. Also verified end-to-end over real HTTP: a live flex-auth serve loaded with this exact registry+policy, hit by qonto-assistant's actual FlexAuthCheckClient (not a mock) -- allow for tenant:friendly:binky, deny (wrong_tenant) for a mismatched tenant. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
36 lines
1 KiB
YAML
36 lines
1 KiB
YAML
id: subjects:qonto-assistant-readers
|
|
tenants:
|
|
- id: tenant:friendly:binky
|
|
name: Binky Hedgehog GmbH
|
|
subjects:
|
|
- id: agent-harness-binky
|
|
type: Agent
|
|
display_name: agent-harness session (binky tenant)
|
|
organization_relation: ServiceProvider
|
|
roles:
|
|
- Operator
|
|
groups:
|
|
- group:qonto-assistant-readers
|
|
tenant: tenant:friendly:binky
|
|
metadata:
|
|
description: >-
|
|
Harness-run agent sessions calling qonto-assistant's
|
|
finance.qonto.read capability over REST or MCP.
|
|
- id: bernd.worsch
|
|
type: Human
|
|
display_name: Bernd Worsch (founder)
|
|
organization_relation: Customer
|
|
roles:
|
|
- Operator
|
|
groups:
|
|
- group:qonto-assistant-readers
|
|
tenant: tenant:friendly:binky
|
|
metadata:
|
|
description: Founder operator, human REST/MCP caller.
|
|
groups:
|
|
- id: group:qonto-assistant-readers
|
|
display_name: qonto-assistant finance.qonto.read callers
|
|
members:
|
|
- agent-harness-binky
|
|
- bernd.worsch
|
|
tenant: tenant:friendly:binky
|