Ratify tenant grouping identifiers
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

This commit is contained in:
tegwick 2026-07-27 20:39:12 +02:00
parent 11a14648c4
commit c3800b6dea

View file

@ -216,12 +216,16 @@ Suggested identifiers:
```text
tenant:platform
tenant:coulomb
tenant:sandbox:<name>
tenant:customer:<name>
tenant:<grouping>:<name>
```
`tenant:platform` is the platform control-plane tenant. Tenant
administration for `tenant:coulomb` or later tenants must never imply
`tenant:platform` is the platform control-plane tenant and `tenant:coulomb`
is the reserved internal/reference tenant. Both are intentionally ungrouped
special cases. External-shaped tenants use a grouping orthogonal to their
capability roles: `trial`, `friendly`, `single`, `small`, `medium`, `large`,
`enterprise`, `consumer`, `family`, `community`, `association`, or `agentic`.
For example, Binky Hedgehog GmbH is `tenant:friendly:binky`. Tenant
administration for `tenant:coulomb` or any grouped tenant must never imply
platform-root authority.
Subjects may have access to multiple tenants, but a token used for a