Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
1.4 KiB
Platform management tenant decision
Date: 2026-09-06 Status: accepted by Bernd Worsch Tracking: GLAS-WP-0015-T03
tenant:platform identifies the platform management, administration and services
tenant: the landlord zone supporting the other tenants. This describes its
operational role; access across tenant boundaries requires explicit policy grants.
For the first Glas production dependency chain, use the exact string
tenant:platform in the approval store configuration, the JWT tenant claims for
secrets-engine-approval and approval-engine-operator, and the secrets-engine
lifecycle CheckRequest tenant. Retain exact tenant comparison and v2 wrong-tenant
denial. Neither bare platform nor tenant:coulomb is an alias.
This decision authorizes alignment of those two proposed service registrations and the undeployed approval service. It does not change unrelated clients, human directory defaults, scopes or other tenant policies. Custody, runtime admission and actual end-to-end verification remain separate outstanding gates.
Owner implementation and evidence are requested on the existing KeyCape, approval-engine, secrets-engine, flex-auth and railiance-platform handoff threads. See platform-tenant-decision-receipts.json for the State Hub decision and delivery receipts. The accepted choice resolves the decision blocker; implementation is not yet verified.