tenant-engine/.claude/rules/architecture.md

28 lines
1.3 KiB
Markdown
Raw Normal View History

## Architecture
Small headless service, modeled on `qonto-assistant`'s layout (same fleet
convention). Layers:
- `domain/` — tenant, grouping, capability-role, and plan-grant models; pure,
no framework dependency.
- `store/` — persistence for tenant records and the role/plan grant audit
trail. In-memory and SQLite back development and tests; PostgreSQL is the
production store (`TEN-WP-0009`).
- `api/` — three surfaces per the boundary contract: a cache-read API
(`key-cape` calls at token issuance), a live-lookup API (`access-engine`
calls synchronously for high-stakes decisions — must fail closed, never
open), and a write API (grant/revoke/plan mutations, authorization-gated
by `flex-auth`, not self-authorized).
- `guardrail/` — shipped (`TEN-WP-0006`/`0007`): spend / entity-count /
action-count ceilings resolved as a total function of grouping, plan,
override, and lifecycle. Contract: `docs/tenant-guardrail-policy.md`.
Full ownership boundary and API contract:
`net-kingdom/canon/standards/tenant-engine-boundary-contract_v0.1.md`.
Claim/carrying mechanism this service implements:
`net-kingdom/canon/standards/iam-profile_v0.3.md` ("Tenant Roles" section).
## Quick Reference
`~/state-hub/mcp_server/TOOLS.md` — MCP tool reference