# Platform management tenant decision Date: 2026-09-06 Status: accepted by Bernd Worsch Tracking: GLAS-WP-0015-T03 `tenant:platform` identifies the platform management, administration and services tenant: the landlord zone supporting the other tenants. This describes its operational role; access across tenant boundaries requires explicit policy grants. For the first Glas production dependency chain, use the exact string `tenant:platform` in the approval store configuration, the JWT tenant claims for `secrets-engine-approval` and `approval-engine-operator`, and the secrets-engine lifecycle CheckRequest tenant. Retain exact tenant comparison and v2 wrong-tenant denial. Neither bare `platform` nor `tenant:coulomb` is an alias. This decision authorizes alignment of those two proposed service registrations and the undeployed approval service. It does not change unrelated clients, human directory defaults, scopes or other tenant policies. Custody, runtime admission and actual end-to-end verification remain separate outstanding gates. Owner implementation and evidence are requested on the existing KeyCape, approval-engine, secrets-engine, flex-auth and railiance-platform handoff threads. See platform-tenant-decision-receipts.json for the State Hub decision and delivery receipts. The accepted choice resolves the decision blocker; implementation is not yet verified.