## Architecture Small headless service, modeled on `qonto-assistant`'s layout (same fleet convention). Layers: - `domain/` — tenant, grouping, capability-role, and plan-grant models; pure, no framework dependency. - `store/` — persistence for tenant records and the role/plan grant audit trail. Starts in-memory/SQLite for early workplans; production backend TBD. - `api/` — three surfaces per the boundary contract: a cache-read API (`key-cape` calls at token issuance), a live-lookup API (`flex-auth` calls synchronously for high-stakes decisions — must fail closed, never open), and a write API (grant/revoke/plan mutations, authorization-gated by `flex-auth`, not self-authorized). - `guardrail/` — reserved namespace, not implemented yet (spend limits, entity/action counts). Full ownership boundary and API contract: `net-kingdom/canon/standards/tenant-engine-boundary-contract_v0.1.md`. Claim/carrying mechanism this service implements: `net-kingdom/canon/standards/iam-profile_v0.3.md` ("Tenant Roles" section). ## Quick Reference `~/state-hub/mcp_server/TOOLS.md` — MCP tool reference