From c3800b6deadfccc117488ada52ae39a63e86757f Mon Sep 17 00:00:00 2001 From: tegwick Date: Mon, 27 Jul 2026 20:39:12 +0200 Subject: [PATCH] Ratify tenant grouping identifiers --- canon/standards/iam-profile_v0.2.md | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/canon/standards/iam-profile_v0.2.md b/canon/standards/iam-profile_v0.2.md index f6d80a3..257fa24 100644 --- a/canon/standards/iam-profile_v0.2.md +++ b/canon/standards/iam-profile_v0.2.md @@ -216,12 +216,16 @@ Suggested identifiers: ```text tenant:platform tenant:coulomb -tenant:sandbox: -tenant:customer: +tenant:: ``` -`tenant:platform` is the platform control-plane tenant. Tenant -administration for `tenant:coulomb` or later tenants must never imply +`tenant:platform` is the platform control-plane tenant and `tenant:coulomb` +is the reserved internal/reference tenant. Both are intentionally ungrouped +special cases. External-shaped tenants use a grouping orthogonal to their +capability roles: `trial`, `friendly`, `single`, `small`, `medium`, `large`, +`enterprise`, `consumer`, `family`, `community`, `association`, or `agentic`. +For example, Binky Hedgehog GmbH is `tenant:friendly:binky`. Tenant +administration for `tenant:coulomb` or any grouped tenant must never imply platform-root authority. Subjects may have access to multiple tenants, but a token used for a