diff --git a/canon/standards/iam-profile_v0.2.md b/canon/standards/iam-profile_v0.2.md index f6d80a3..257fa24 100644 --- a/canon/standards/iam-profile_v0.2.md +++ b/canon/standards/iam-profile_v0.2.md @@ -216,12 +216,16 @@ Suggested identifiers: ```text tenant:platform tenant:coulomb -tenant:sandbox: -tenant:customer: +tenant:: ``` -`tenant:platform` is the platform control-plane tenant. Tenant -administration for `tenant:coulomb` or later tenants must never imply +`tenant:platform` is the platform control-plane tenant and `tenant:coulomb` +is the reserved internal/reference tenant. Both are intentionally ungrouped +special cases. External-shaped tenants use a grouping orthogonal to their +capability roles: `trial`, `friendly`, `single`, `small`, `medium`, `large`, +`enterprise`, `consumer`, `family`, `community`, `association`, or `agentic`. +For example, Binky Hedgehog GmbH is `tenant:friendly:binky`. Tenant +administration for `tenant:coulomb` or any grouped tenant must never imply platform-root authority. Subjects may have access to multiple tenants, but a token used for a