Bootstrap repo: State Hub registration, agent docs, TEN-WP-0001/0002
statehub register + repo-seed template scaffold (CLAUDE.md, .claude/rules/,
registry/). INTENT.md and SCOPE.md rewritten from the generated stub to
match net-kingdom's ratified tenant-engine-boundary-contract_v0.1.md
(Purpose, Responsibility Boundary, Non-Goals). topic_slug corrected from
the auto-assigned custodian default to netkingdom, matching key-cape and
user-engine.
TEN-WP-0001 (bootstrap) complete: files reviewed/refined, stack decided
(Python 3.12 + FastAPI, matching qonto-assistant's convention), first real
workplan seeded.
TEN-WP-0002 drafted: service skeleton, domain model (tenant/grouping/
capability-role/plan-grant), storage layer, and the three boundary-contract
API surfaces (cache-read for key-cape, live-lookup for flex-auth with an
explicit fail-closed requirement, write API behind a WriteAuthorizer seam
since real flex-auth integration is a declared non-goal for this pass).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 21:56:07 +02:00
|
|
|
## Architecture
|
|
|
|
|
|
|
|
|
|
Small headless service, modeled on `qonto-assistant`'s layout (same fleet
|
|
|
|
|
convention). Layers:
|
|
|
|
|
|
|
|
|
|
- `domain/` — tenant, grouping, capability-role, and plan-grant models; pure,
|
|
|
|
|
no framework dependency.
|
|
|
|
|
- `store/` — persistence for tenant records and the role/plan grant audit
|
2026-09-07 00:21:03 +02:00
|
|
|
trail. In-memory and SQLite back development and tests; PostgreSQL is the
|
|
|
|
|
production store (`TEN-WP-0009`).
|
Bootstrap repo: State Hub registration, agent docs, TEN-WP-0001/0002
statehub register + repo-seed template scaffold (CLAUDE.md, .claude/rules/,
registry/). INTENT.md and SCOPE.md rewritten from the generated stub to
match net-kingdom's ratified tenant-engine-boundary-contract_v0.1.md
(Purpose, Responsibility Boundary, Non-Goals). topic_slug corrected from
the auto-assigned custodian default to netkingdom, matching key-cape and
user-engine.
TEN-WP-0001 (bootstrap) complete: files reviewed/refined, stack decided
(Python 3.12 + FastAPI, matching qonto-assistant's convention), first real
workplan seeded.
TEN-WP-0002 drafted: service skeleton, domain model (tenant/grouping/
capability-role/plan-grant), storage layer, and the three boundary-contract
API surfaces (cache-read for key-cape, live-lookup for flex-auth with an
explicit fail-closed requirement, write API behind a WriteAuthorizer seam
since real flex-auth integration is a declared non-goal for this pass).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 21:56:07 +02:00
|
|
|
- `api/` — three surfaces per the boundary contract: a cache-read API
|
2026-09-07 00:21:03 +02:00
|
|
|
(`key-cape` calls at token issuance), a live-lookup API (`access-engine`
|
|
|
|
|
calls synchronously for high-stakes decisions — must fail closed, never
|
|
|
|
|
open), and a write API (grant/revoke/plan mutations, authorization-gated
|
|
|
|
|
by `flex-auth`, not self-authorized).
|
|
|
|
|
- `guardrail/` — shipped (`TEN-WP-0006`/`0007`): spend / entity-count /
|
|
|
|
|
action-count ceilings resolved as a total function of grouping, plan,
|
|
|
|
|
override, and lifecycle. Contract: `docs/tenant-guardrail-policy.md`.
|
Bootstrap repo: State Hub registration, agent docs, TEN-WP-0001/0002
statehub register + repo-seed template scaffold (CLAUDE.md, .claude/rules/,
registry/). INTENT.md and SCOPE.md rewritten from the generated stub to
match net-kingdom's ratified tenant-engine-boundary-contract_v0.1.md
(Purpose, Responsibility Boundary, Non-Goals). topic_slug corrected from
the auto-assigned custodian default to netkingdom, matching key-cape and
user-engine.
TEN-WP-0001 (bootstrap) complete: files reviewed/refined, stack decided
(Python 3.12 + FastAPI, matching qonto-assistant's convention), first real
workplan seeded.
TEN-WP-0002 drafted: service skeleton, domain model (tenant/grouping/
capability-role/plan-grant), storage layer, and the three boundary-contract
API surfaces (cache-read for key-cape, live-lookup for flex-auth with an
explicit fail-closed requirement, write API behind a WriteAuthorizer seam
since real flex-auth integration is a declared non-goal for this pass).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 21:56:07 +02:00
|
|
|
|
|
|
|
|
Full ownership boundary and API contract:
|
|
|
|
|
`net-kingdom/canon/standards/tenant-engine-boundary-contract_v0.1.md`.
|
|
|
|
|
Claim/carrying mechanism this service implements:
|
|
|
|
|
`net-kingdom/canon/standards/iam-profile_v0.3.md` ("Tenant Roles" section).
|
|
|
|
|
|
|
|
|
|
## Quick Reference
|
|
|
|
|
|
|
|
|
|
`~/state-hub/mcp_server/TOOLS.md` — MCP tool reference
|