net-kingdom/docs/adr
tegwick 9026d7f904
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 5s
ADR-0014 + tenant-engine boundary contract + IAM Profile v0.3
Ratifies the tenant capability-role model (PLTF/IAM/VEN/CUS, non-exclusive,
independent of ADR-0013's grouping axis), a hybrid carrying mechanism
(tenant-engine authoritative, key-cape caches a tenant_roles claim at
issuance, flex-auth re-validates live for aal2-class decisions), and
tenant-engine as a new, separate service owning tenant existence, grouping,
capability roles, and plan/subscription assignment -- not a module inside
user-engine, whose own boundary contract already scopes it to consuming
tenant identifiers, not owning them.

canon/standards/tenant-engine-boundary-contract_v0.1.md defines that
ownership boundary before the repo exists, mirroring how
user-engine-boundary-contract_v0.1.md was sequenced.

canon/standards/iam-profile_v0.3.md (minor version per ADR-0011's own
governance -- optional claim addition, no breaking change) adds the
tenant_roles claim, folds in ADR-0013's tenant-identifier vocabulary, and
documents the live-revalidation requirement. docs/platform-identity-
security-architecture.md's Tenant Model section and SCOPE.md's canonical
spec pointer updated to match; other historical citations of v0.2 left as
version-pinned references, not bulk-updated.

Records Bernd's trial-tenant policy: trial-grouped tenants may hold any
capability role (showcase/test/explore), with safety enforced through
tenant-engine-owned resource guardrails (spend limits, entity/action
counts) rather than role gating -- guardrail design is reserved, explicitly
not specified by this change.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 21:45:37 +02:00
..
ADR-0006-recursive-multi-tenant-identity-authorization.md Document recursive platform security architecture 2026-05-17 12:18:29 +02:00
ADR-0007-security-orchestration-boundary.md Add meta-orchestration layer to ADR-0007; deepen NetKingdom INTENT 2026-05-21 01:00:39 +02:00
ADR-0008-object-storage-sts-credential-vending.md Add OpenBao runtime secret authority; complete NK-WP-0006/0007/0008 2026-05-20 22:51:20 +02:00
ADR-0010-orchestration-vs-dependency-self-coherent-intent.md Add responsibility map; link from ADR-0010 2026-05-21 02:05:37 +02:00
ADR-0011-iam-profile-ownership-and-version-governance.md Implement NK-WP-0012 IAM profile specification 2026-05-22 14:35:31 +02:00
ADR-0012-playbook-capability-contract-ownership.md Implement NK-WP-0013 playbook capability contract 2026-05-22 14:49:25 +02:00
ADR-0013-tenant-onboarding-grouping-taxonomy.md ADR-0013: tenant onboarding grouping taxonomy, orthogonal to capability role 2026-07-23 16:01:55 +02:00
ADR-0014-tenant-capability-roles-and-tenant-engine-ownership.md ADR-0014 + tenant-engine boundary contract + IAM Profile v0.3 2026-07-23 21:45:37 +02:00